US government agencies have until 24 August to apply the fix for Zimbra CVE-2026-73570, a remote code execution flaw that CISA added to its Known Exploited Vulnerabilities catalogue on Friday after confirming active exploitation in the wild. The race to patch is already being lost on parts of the internet: eSecurityPlanet reports that Shadowserver found at least 8,200 unpatched Zimbra servers still reachable online.
The vulnerability sits in the SNMP monitoring component of Zimbra Collaboration Suite (ZCS). When SNMP notifications are enabled, improper sanitisation of untrusted input means an unauthenticated attacker can send specially crafted SMTP requests that execute arbitrary operating system commands as the Zimbra user. No credentials required, which goes a long way to explaining why it drew so much attention so quickly.
Zimbra CVE-2026-73570 CISA pressure comes as compromise counts accelerate
The speed of exploitation is the number that jumps out. According to Gblock, the count of compromised Zimbra Collaboration Suite instances rose from 155 on 20 August to 274 on 22 August, a near-doubling in two days. On Monday, Shadowserver reported finding over 270 compromised instances while scanning for CVE-2026-73570 exploitation artefacts, and the numbers were still climbing when CISA issued its binding directive.
Gblock also notes that NIST’s National Vulnerability Database scored CVE-2026-73570 at 8.9, placing it firmly in the high-severity band. That score was published on 13 August 2026, a full 24 days after Zimbra shipped the patch in version 10.1.20 on 20 July. That lag matters: organisations that rely on NVD alerts rather than watching vendor release notes directly had a narrow window to act before attackers were already through the door.
CERT Polska, the Polish computer emergency response team, was the first to flag the flaw as being targeted in the wild, raising the alarm last Monday. CISA confirmed the alert on Friday, formalised the KEV listing, and gave US Federal Civilian Executive Branch (FCEB) agencies three days to secure their systems. While Shadowserver tracks more than 12,000 Zimbra servers exposed on the internet, that figure includes honeypots and instances that may already be patched, so the true pool of vulnerable targets is harder to pin down.
For teams assessing their own exposure, CERT Polska asked security staff to check logs for signs of post-exploitation activity: specifically, the Zimbra service restarting unexpectedly, and files created in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ by the zimbra user over the previous 30 days. It is a reasonably tight forensic checklist for a flaw that was clearly being weaponised before most defenders had a patch notification.
A familiar pattern: Zimbra under sustained state and criminal fire
This is not a one-off for ZCS. The platform, used by hundreds of millions of organisations and individuals worldwide including hundreds of government agencies, has been targeted repeatedly in recent years. Seqrite Labs researchers revealed in March that APT28, a state-sponsored threat group linked to Russia’s military intelligence service, was exploiting a stored cross-site scripting (XSS) vulnerability in attacks against Ukrainian government ZCS servers. In October 2024, US and UK cyber agencies warned that APT29 hackers (also tracked as Midnight Blizzard and Cozy Bear), linked to Russia’s Foreign Intelligence Service, were targeting Zimbra using a flaw previously used to harvest email credentials. Russian Winter Vivern cyber spies have also abused a reflected XSS vulnerability to steal emails from NATO-aligned targets via Zimbra webmail portals.
The pattern is consistent enough that ZCS servers should probably be treated as a standing target rather than an occasional one. Patching to version 10.1.20 closes the CVE-2026-73570 hole; the 24 August deadline for FCEB agencies makes that the floor, not the ceiling, for anyone still running an older build.

