Attackers Exploit Zimbra CVE-2026-73570; Patch Available
Poland’s CERT Polska warns attackers are exploiting CVE-2026-73570 in Zimbra Collaboration servers patched in 10.1.20. The flaw allows unauthenticated OS command execution when zimbra-snmp and SNMP notifications are enabled.
Poland’s CERT Polska reported active exploitation of CVE-2026-73570, a high-severity vulnerability in Zimbra Collaboration servers. Zimbra released version 10.1.20 on July 20 with a fix for the bug.
The vulnerability can be triggered without authentication when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An attacker who exploits the flaw can execute arbitrary operating-system commands as the Zimbra user.
CERT Polska observed exploitation attempts this week and published indicators of compromise to help defenders. The agency did not disclose the size, origin or motive of the campaign.
An exploited server can provide attackers with persistence, access to hosted email accounts, credential harvesting and the ability to move laterally to other systems on the same network. Installations that do not have zimbra-snmp installed or that have SNMP notifications disabled are not affected by this specific issue.
U.S. cybersecurity authorities track Zimbra flaws. The Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog currently lists 18 Zimbra Collaboration Suite vulnerabilities; CVE-2026-73570 has not been added to that catalog.
Zimbra administrators should verify whether zimbra-snmp and SNMP notifications are enabled on their systems and apply the 10.1.20 update if they have not done so. Organizations that cannot patch immediately should consider disabling SNMP notifications, reviewing the published indicators of compromise, inspecting logs and mail access for unusual activity, resetting credentials where needed and following incident response procedures.
Security teams should scan exposed mail servers and monitor for suspicious command execution or persistence mechanisms tied to the Zimbra user.








