Future TechnologyFuture Technology
Security

Zimbra's SNMP Flaw Is Being Exploited and the Deadline Is Today

· 3 min read · Future Technology

Key takeaways

  • CVE-2026-73570 is an unauthenticated remote code execution flaw in Zimbra Collaboration Suite, patched on 20 July
  • CERT Polska confirmed active exploitation; CISA added it to the KEV catalogue and set a three-day federal patch window closing 24 August
  • Shadowserver counts over 12,100 exposed Zimbra servers and has already found more than 270 compromised instances

A mail server that answers to anyone who asks is a bad mail server. That is roughly the shape of Zimbra CVE-2026-73570, an unauthenticated remote code execution flaw that Zimbra patched on 20 July and that attackers started using in the wild barely a month later.

What the flaw actually does

The bug lets an unauthenticated attacker run arbitrary shell commands with the privileges of the zimbra user. No credentials, no phishing step, no waiting for someone to click anything.

The trigger sits in an unglamorous corner of the stack. Instances are affected when the SNMP trap service is enabled through the snmp_notify parameter and the swatchdog service is running. Both are on by default, which is the part worth reading twice. This is not an edge case that only bites unusual deployments; it is the shipping configuration.

Why this one escalated so fast

CERT Polska spotted exploitation in the wild and raised the alarm. CISA confirmed it, added CVE-2026-73570 to its Known Exploited Vulnerabilities catalogue, and ordered US Federal Civilian Executive Branch agencies to fix or disconnect within three days. That window closes today, 24 August.

Three days is the short end of CISA's scale, and it gets used when exploitation is confirmed rather than theoretical. We covered that mechanism in more detail in our piece on CISA's three-day patch window, and this is a textbook case of the conditions that trigger it.

The exposure numbers explain the urgency. Shadowserver has identified more than 12,100 Zimbra servers reachable from the internet, with roughly 4,492 in Asia and 4,382 in Europe. While scanning for exploitation artefacts, the same organisation found over 270 instances that had already been compromised.

What to do about it

Patch, obviously. Then check whether you were already hit, because a month of public patch availability is also a month of window for anyone reading the diff. Look at the zimbra user's command history, scheduled tasks, and anything new in web-accessible directories since late July. If SNMP trapping is not something your deployment needs, turning it off is a reasonable belt-and-braces move on top of the update.

For context on how a flaw like this ends up rated the way it is, our explainer on reading a CVSS score covers what "unauthenticated, network, no user interaction" does to the maths. It is the combination that turns a mail server into a shell.

Self-hosted collaboration software is a reasonable thing to run. It is just software that has to be patched on the day, not the quarter. The 943 fixes Oracle shipped this month make the same point from a different direction.

Read next

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.