Cybersecurity & Protection

Zimbra Servers Under Attack: Up to 12,000 Systems at Risk

Aug 21, 2026 3 min read
All articles

Attackers are exploiting a dangerous security vulnerability in the widely used email and groupware solution Zimbra Collaboration Suite (ZCS) to inject and execute their own code on vulnerable systems. An update has closed the flaw since mid-July; if you run a Zimbra instance, you should secure it urgently.

Unpatched SNMP processing as the entry point

The exploited vulnerability is CVE-2026-73570. With a CVSS score of 8.9, it narrowly misses a critical rating. According to the description, the cause is insufficient sanitization of untrusted input when processing SNMP notifications. Attackers can send specially crafted SNMP requests without prior authentication and use them to execute their own commands in the context of the Zimbra user on vulnerable servers. For the flaw to be exploitable, though, the zimbra-snmp package must be installed and SNMP notifications enabled.

Patch available, attacks already underway

All Zimbra versions before 10.1.20 are considered vulnerable. That version was released on July 20 and includes further security fixes alongside the patch for CVE-2026-73570. Since attackers are already actively exploiting the flaw, you should apply the update urgently if you haven't already. Poland's Computer Emergency Response Team (CERT PL) recently issued an attack warning for CVE-2026-73570. Besides updating vulnerable servers, it recommends searching Zimbra logs and certain system directories for signs of past attacks and taking further action if needed.

Thousands of servers reachable worldwide

According to scans by the Shadowserver Foundation, more than 12,000 Zimbra servers are currently reachable over the internet worldwide, around 4,400 of them in Europe and 800 in Germany. How many of those remain unpatched and thus vulnerable via CVE-2026-73570 is unclear. Earlier warnings from Germany's BSI, however, showed that many German Zimbra servers are often run on outdated versions for a long time, a pattern that could quickly backfire given the ongoing attacks.