Zimbra Under Attack: SNMP Vulnerability with CVSS 8.9 Has Already Compromised at Least 274 Public Servers

CVE-2026-73570 allows for remote code execution without authentication on Zimbra servers with SNMP enabled by default. CISA has imposed a three-day deadline for federal agencies, and the patch window is tightening.
The vulnerability CVE-2026-73570 in the Zimbra Collaboration Suite has entered an active exploitation campaign. Independent researchers have identified at least 274 compromised public instances, according to a survey reported by Help Net Security on Tuesday, August 25. The flaw, rated CVSS 8.9, allows remote code execution without authentication through the processing of SNMP notifications, a feature that is enabled by default in the affected versions.
The attack path is direct. According to the technical description, the processing of SNMP notifications in Zimbra does not properly sanitize untrusted input. An attacker sends specifically crafted SMTP requests and gains arbitrary command execution with Zimbra user privileges, effectively taking control of the entire email server. This is not a narrow authentication bypass; it is complete control of the host.
Timing Matters
Zimbra Networks disclosed the CVE on June 26 and released the patched version 10.1.20 on July 20. On August 17, CERT Polska issued a public alert regarding active exploitation. CISA included the flaw in its Known Exploited Vulnerabilities catalog and set a three-day deadline for federal civil agencies to apply the patch, which is a shorter timeframe than the usual fifteen days provided by this mechanism. Approximately seven weeks elapsed between the disclosure and the first public report of a production compromise.
Seven weeks used to be a comfortable timeframe for corporate patch windows. It is no longer. Analysts specializing in continuous threat exposure management, such as SafeBreach, have been indicating since the Zerologon incident that the useful patch window is shrinking from quarters to weeks for unauthenticated RCE vulnerabilities with public PoCs.
Who Runs Zimbra Outside of the U.S.
Zimbra is dominant in sectors where Exchange and Microsoft 365 have not penetrated, whether due to cost, data control, or open-source preference. In the U.S., it is found in universities, mid-sized businesses, and some state agencies. In Europe, it is common in French, Italian, and Eastern European ministries, as well as public health operators. In Southeast Asia, it appears in government contracts in Vietnam and the Philippines. In Latin America, it is the standard platform in various Brazilian state secretariats and ministries in Argentina, Mexico, and Colombia.
The common pattern in almost all these regions is the same: operations are delegated to local integrators with small teams and maintenance window cycles defined by committees. Seven weeks for applying an emergency patch does not fit into this model. This is why the affected base tends to be disproportionately public.
What Zimbra Says and What CISA Imposes
Zimbra Networks confirmed the existence of CVE-2026-73570 in its June security bulletin and made the update available in July. The company had not issued any additional communication regarding the number of compromised instances by the time this article was published. CISA, for its part, acted with a shorter timeframe than usual, indicating a risk assessment of imminent threat. The number of 274 compromised servers comes from external scans, not from internal audits by the operators, suggesting that the actual total is higher.
What the CIO Needs to Do This Week
Zimbra instances still running on versions prior to 10.1.20 should be treated as compromised until proven otherwise. Immediate isolation, checking for web shells planted by attackers, analyzing SNMP and SMTP logs, and revalidating credentials are the first steps. The default configuration of SNMP notifications needs to be reviewed even after the patch, particularly in multi-tenant environments and in managed services that operate Zimbra for multiple clients.
For integrators operating Zimbra on behalf of public clients, this case changes the contractual discussion. Patch SLAs written based on monthly windows have become obsolete over the past eighteen months, and the next renewal will need to reflect this new reality. This case also confirms a thesis security architects have been advocating for two years: continuous threat exposure management is not about a complete inventory of CVEs. It is about reducing the time between a patch being published and a patch being deployed, focusing on a short list of vulnerabilities that are likely to be exploited. Zimbra in July was one of them. Public sectors across three continents now carry the evidence.