Tech News

Zimbra: 270+ Mail Servers Compromised via CVE-2026-73570

274 Zimbra servers exposed on the web show signs of compromise through a new security flaw: CVE-2026-73570. If you have not patched your server yet, it is time to act. Here is what you need to know.

A command injection that goes through SNMP

On August 17, 2026, the Polish CERT team published a notice about the active exploitation of a security flaw in Zimbra Collaboration Suite. In its advisory, it references CVE-2026-73570, a vulnerability that allows command execution at the operating system level.

That said, this security flaw is not exactly new: it was permanently patched on July 20, 2026, a little over a month ago. But all this time, it appears to have been a gift for some cybercriminals. Several analyses from The Shadowserver point in that direction, highlighting a spike in compromised instances around August 22.

On August 20, 2026, The Shadowserver counted 155 compromised instances. Forty-eight hours later, that figure had climbed to 274 compromised instances, with the United States at the top of the list. The map published by The Shadowserver also shows 21 compromised Zimbra mail servers in France. On that same date, more than 8,000 instances were still running a vulnerable version: potential targets.

Current map with up-to-date data retrieved this morning.

However, not all Zimbra servers exposed on the web are vulnerable. Beyond the version in use, this flaw resides in Zimbra's SNMP component. In other words, a specially crafted SNMP request can be used to execute commands directly on the Zimbra server's OS.

In practice, three conditions must be met for exploitation to be possible:

  • The optional zimbra-snmp package must be installed on the server.
  • SNMP notifications must be enabled via the snmp_notify parameter.
  • The swatchdog service, which processes these notifications, must be running. The Polish CERT notes that it is enabled by default.

How can you protect yourself?

The advisory published by Zimbra on July 20 accompanied the release of Zimbra Collaboration Suite 10.1.20 and mentioned a permanent security fix for CVE-2026-73570. Yes, because before that, a security bulletin dated June 26, 2026, described a temporary mitigation for this vulnerability.

You must therefore install at least this version to protect yourself from this vulnerability. But patching is not enough if the attacker has already been through... In the Polish CERT notice, two checks are also mentioned:

  • In /var/log/zimbra.log, look for entries such as Service status change: <charge malveillante> changed from stopped to running, as well as the reverse transition.
  • Files created in the last 30 days by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ and /tmp/.

Since then, other agencies have followed suit. For example, CISA added the vulnerability to its KEV catalog on August 21, 2026. Before that, in France, CERT-FR published advisory CERTFR-2026-AVI-1041 on August 19, covering all vulnerabilities fixed in version 10.1.20.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.