Future TechnologyFuture Technology
Security

Zimbra CVE-2026-73570 Is Under Attack and 12,000 Servers Are Still Reachable

· 3 min read · By Future Technology

Key takeaways

  • CVE-2026-73570 allows unauthenticated remote command execution as the Zimbra user when the optional zimbra-snmp package is installed and SNMP notifications are enabled
  • The fix shipped in Zimbra 10.1.20 on 20 July, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 21 August
  • Shadowserver counts more than 12,000 internet-reachable Zimbra instances and over 270 showing signs of compromise
  • Citrix NetScaler CVE-2026-8452, patched 30 June, was added to KEV on 26 August with a 29 August federal deadline

The patch has been available since 20 July. Shadowserver still counts more than 12,000 Zimbra servers reachable from the internet, and over 270 of them showing signs of compromise. Zimbra CVE-2026-73570 is not a zero day. It is a maintenance failure with a CVE number attached.

What the flaw does

CVE-2026-73570 is an unauthenticated remote command execution bug in Zimbra Collaboration Suite. The attacker needs no credentials. If the conditions are met, they run operating system commands as the Zimbra user, which on most deployments is enough to read every mailbox on the box.

The conditions narrow it slightly. The flaw only triggers where the optional zimbra-snmp package is installed and SNMP notifications are switched on. That is a common configuration on managed mail servers rather than a universal one, so the exposed population is smaller than the total Zimbra install base. It is clearly not small enough. CERT Polska observed the exploitation in the wild, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 21 August under BOD 22-01, which gives US federal agencies three days to remediate.

The NetScaler one alongside it

CVE-2026-8452 in Citrix NetScaler follows the same shape. Patched on 30 June, added to KEV on 26 August with a 29 August deadline. WatchTowr demonstrated unauthenticated remote code execution against it.

Different vendors, different products, identical timeline. Both had fixes published more than a month before anyone was exploited at scale.

What to do today

Check whether the vulnerable package is present at all. On Zimbra, that means confirming whether zimbra-snmp is installed and whether SNMP notifications are enabled, then checking your version against 10.1.20. If you are behind, patch first and investigate second, because the compromise numbers say the window has already been open for weeks.

After patching, assume the box may already have been touched. Look for unexpected processes running as the Zimbra user, new cron entries, modified webmail templates and outbound connections to addresses nobody recognises. NetScaler admins should confirm they are past the 30 June build and review session logs for the same period.

If you run either of these behind a public IP without a reason, that is the part worth fixing permanently rather than monthly. Our seven-step exposure check for anything you self-host walks through narrowing that surface, and the same discipline applies to endpoints, which is where the Android security checklist picks up.

The gap is the whole story

Neither of these attacks required a novel technique. The interval between patch published and patch applied is the entire attack surface here, and in both cases that interval ran to roughly two months.

That is a resourcing problem rather than a knowledge problem. Nobody in these organisations failed to understand that patching mail servers matters, they failed to have the time. Exotic bugs like the KVM Januscape VM escape take the headlines, while the servers actually being taken over this month are the ones missing a fix that shipped in July.

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.