Fraud Management & Cybercrime,
Governance & Risk Management,
Patch Management
More Than 8,000 Unpatched Instances Remain Exposed to CVE-2026-73570

A significant security vulnerability in the Zimbra office productivity software suite has been documented, revealing that 267 instances have been compromised globally as of the most recent report. Furthermore, upwards of 8,000 instances remain vulnerable due to unpatched flaws, according to recent analyses.
The vulnerability, designated as CVE-2026-73570, carries a critical CVSS score of 8.9, indicating its severity. This remote code execution vulnerability within the Synacor-owned Zimbra Collaboration Suite is believed to be the underlying cause of these compromises, as highlighted by the threat intelligence data provider, ShadowServer.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that active exploitation of this vulnerability is ongoing. CISA mandated that federal agencies apply patches by the following Monday to mitigate the threat. This urgency underscores the potential risks associated with the flaw, which permits unauthenticated attackers to execute arbitrary operating system commands by sending specially crafted SMTP requests—indicated in the Known Exploited Vulnerabilities catalog.
The vulnerability was first disclosed by Zimbra on June 26, achieving initial awareness of the issue. Following the disclosure, Zimbra provided temporary mitigation measures and subsequently released a patch on July 20. The first indications of exploitation were reported by Poland’s governmental threat response team, CERT Polska, on August 17. ShadowServer commenced tracking the exploitations shortly thereafter, observing a notable concentration of affected systems in Europe.
Data sourced from ShadowServer indicates that Europe represents the largest share of the compromised instances. However, as of Monday, the United States emerged as the country with the highest number of affected instances, tallying up to 46 compromised systems. This statistic emphasizes the vulnerability’s widespread impact and the potential risks faced by organizations that rely on Zimbra’s services.
The root cause of this troubling vulnerability lies in improper sanitization practices, which allow untrusted input to infiltrate the Simple Network Management Protocol (SNMP) workflow. This manipulation can lead to unauthorized execution of operating system commands, as analyzed by the threat intelligence firm SocRadar. Their findings indicate that Zimbra mail servers frequently operate in internet-facing environments, which increases their susceptibility to attacks.
Furthermore, the exploitation of this vulnerability poses serious risks, as it enables attackers to gain unauthorized access to sensitive mail data, critical configuration files, and local system resources. With all versions of Zimbra released prior to 10.1.20 being affected, ShadowServer identified thousands of such vulnerable instances predominantly in countries like Indonesia, the U.S., and France.
In light of these revelations, SocRadar has advised that administrators managing unpatched Zimbra installations conduct thorough checks. Specifically, they should verify the presence of the optional zimbra-snmp package, along with the snmp_notify notification setting and the swatchdog service. These components represent conditions that can facilitate exploitation, adding another layer of urgency for system administrators to address these vulnerabilities promptly.
This situation serves as a critical reminder of the importance of maintaining up-to-date security protocols, particularly for software that is extensively utilized across various internet-facing applications. As cybersecurity threats continue to evolve, the emphasis must be placed on proactive risk management and the consistent application of patches to safeguard sensitive data and organizational assets.

