// news

Zimbra CVE-2026-73570 Actively Exploited: Unauthenticated RCE via SNMP

Attackers are actively exploiting CVE-2026-73570 in Zimbra Collaboration (ZCS). It’s a command-injection flaw in the SNMP monitoring component: under a specific configuration an unauthenticated attacker executes OS commands as the zimbra user. Per the Shadowserver Foundation, 274 servers were already compromised by 22 August (up from 155 two days earlier), with roughly 8,200 installations still unpatched.

The key caveat: the bug only fires in a non-default configuration — the optional zimbra-snmp package installed and SNMP notifications enabled. The trigger is specially crafted SMTP requests. Synacor disclosed it on 26 June and fixed it in ZCS 10.1.20 (20 July); CISA added it to the KEV catalog with a 24 August federal deadline.

Why a patch alone isn’t enough

If the server was internet-facing in the vulnerable configuration, assume breach. The patch closes the door but doesn’t evict anyone already inside. After updating, hunt for:

  • web shells and stray files in the Zimbra web root, anomalous cron jobs and systemd units;
  • modified or deleted logs, new SSH keys, suspicious processes owned by zimbra;
  • outbound connections to unknown hosts (C2), new mail-forwarding rules, added admin accounts.

A mail server is a goldmine: correspondence, attachments, credentials, and password-reset tokens for other services. RCE there escalates into a whole-org compromise fast.

What to do

Patch to ZCS 10.1.20+ now; until then, disable SNMP notifications and restrict server access by IP. Regular external network penetration testing finds exposed services and unsafe configs before an attacker does, and an assumed-breach assessment shows how far a foothold could reach. Get in touch and we’ll check your perimeter.

Sources: Shadowserver Foundation; BleepingComputer, Help Net Security, The Hacker News; Synacor/Zimbra advisory; CISA KEV.

// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement