Safety#Security scan

Zimbra flaw CVE-2026-73570 exploited in the wild: patch shipped three weeks before disclosure

The unauthenticated command-injection flaw CVE-2026-73570 in ZCS has been exploited since late July to steal email; 274 servers compromised, fix in ZCS 10.1.20.

Red alert triangles over a code background

Ars Technica reported on September 30 that a critical Zimbra Collaboration Suite flaw, CVE-2026-73570, is being exploited to steal email. The unauthenticated command injection fires when a crafted SMTP request hits ZCS’s SNMP notification path, executing shell commands as the zimbra service account; it requires the optional zimbra-snmp package with notifications enabled.

Facts

  • The flaw: CVE-2026-73570, unauthenticated command injection via the SMTP-triggered SNMP notification path; requires the optional zimbra-snmp package.
  • Exploitation: Microsoft observed two scanning tools probing vulnerable endpoints July 28–August 7, followed by web shell deployment, privilege escalation and mailbox/credential theft; the actors remain unidentified.
  • Disclosure lag: Synacor released the fix on July 20 but disclosed the vulnerability only three-plus weeks later.
  • Scale: Shadowserver tracks 274 compromised instances; exposed servers dropped from ~19,000 after the patch to ~10,000 now.
  • Fix: upgrade to ZCS 10.1.20 or later.

Editorial take

The classic self-hosted email timeline: patch available, disclosure late, scanning in the wild. ZCS admins should do three things today — upgrade to 10.1.20+, check whether zimbra-snmp is enabled (disable it if unused), and hunt for web shells and anomalous credential access. Email is the root of every password-reset chain; a compromised mail server costs far more than one box, and services can be exposure-checked regularly with a tool like Web Check.