Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
ID: 1de38491-546d-535d-b93e-ad3cb728c91e
STIX ID: report--1de38491-546d-535d-b93e-ad3cb728c91e
Feed Name: Help Net Security
At least 274 internet-facing Zimbra instances have been compromised via CVE-2026-73570, a code-injection flaw in the optional zimbra-snmp package that allows unauthenticated attackers to run OS commands as the Zimbra user; the vulnerability was patched in ZCS v10.1.20 (July 20, 2026), Polish CERT and Shadowserver reported active exploitation and indicators of compromise, and CISA added the CVE to its Known Exploited Vulnerabilities list while warning many instances remain unpatched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
