Attackers are actively exploiting CVE-2026-73570, a critical unauthenticated remote code execution flaw in Zimbra Collaboration Suite, according to CERT Polska. The vulnerability is an OS command injection issue in Zimbra's SNMP monitoring functionality that can be triggered with specially crafted SMTP requests when the optional zimbra-snmp package is installed, SNMP notifications are enabled, and the swatchdog service is running. Successful exploitation allows arbitrary command execution as the zimbra user, enabling web shell deployment, mailbox theft, persistence, and broader compromise.
Zimbra patched the flaw in version 10.1.20, and defenders are being urged to update immediately because exploitation has already been observed in the wild. CERT Polska recommended reviewing zimbra.log for suspicious activity, checking for unexpected Zimbra service restarts, and inspecting files created by the zimbra user in web application and temporary directories for malicious artifacts. Shadowserver reported that more than 12,100 internet-exposed Zimbra servers remain reachable, mainly in Europe and Asia, underscoring the scale of potential exposure.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
A ProjectDiscovery nuclei-templates pull request published detailed technical analysis and proof-of-concept payloads for CVE-2026-73570, showing how crafted SMTP VRFY input can reach Zimbra's SNMP handling and trigger command injection via dosnmp() and snmptrap execution. The submission included callback-based verification examples and artifact details such as zimbra.log parsing and /tmp output creation.
Shadowserver observed 274 internet-exposed Zimbra instances with exploitation artifacts from attacks exploiting CVE-2026-73570. It also said at least 8,200 unpatched Zimbra instances remained exposed online, while noting the flaw requires a non-default configuration.
CISA added Zimbra Collaboration Suite flaw CVE-2026-73570 to its Known Exploited Vulnerabilities catalog on 2026-08-21, identifying it as an OS command injection issue that can be exploited via crafted SMTP requests. The agency directed organizations to apply vendor mitigations and follow BOD 26-04 and its Forensics Triage Requirements.
Shadowserver Foundation identified 155 internet-facing Zimbra instances compromised through exploitation of CVE-2026-73570. The report marked a quantified escalation of the campaign, which later grew to at least 274 affected systems.
Zimbra fixed the critical command injection vulnerability CVE-2026-73570 in Zimbra Collaboration Suite with the release of version 10.1.20. The vendor advisory said the update addresses command injection in the SNMP monitoring component when notifications are enabled.
Zimbra disclosed CVE-2026-73570, a critical unauthenticated remote code execution flaw in Zimbra Collaboration Suite caused by improper sanitization during SNMP notification processing. The issue can be exploited via crafted SMTP requests when SNMP notifications are enabled.
Reported compromises exploiting CVE-2026-73570 deployed cryptominer or backdoor payloads under /dev/shm and established persistence through the zimbra user's crontab, including an entry executing /dev/shm/.khp every minute. The report also identified associated suspicious filenames and advised containment before cleanup to prevent reinfection.
CERT Polska published defender guidance for investigating possible exploitation, including reviewing zimbra.log for suspicious service-status messages and checking files created by the zimbra user. It also highlighted webapps and /tmp directories as key locations to inspect for web shells, scripts, archives, or other suspicious artifacts.
CERT Polska warned that threat actors are actively exploiting CVE-2026-73570, a critical unauthenticated remote code execution flaw in Zimbra Collaboration Suite. The flaw can be triggered via crafted SMTP requests against deployments with the vulnerable SNMP notification setup.
After learning of CVE-2026-73570 in June, Synacor issued a temporary mitigation for the Zimbra SNMP command-injection flaw before releasing the permanent fix in Zimbra Collaboration Suite 10.1.20.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
29 references tracked. Mallory keeps watching after this page renders.
nki.gov.hu
Open sourcereddit.com
Open sourceitpro.com
Open sourcebleepingcomputer.com
Open sourcemoje.cert.pl
Open sourcecve.org
Open sourcegov.br
Open sourcewiki.zimbra.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.