we_are_coded.by CODE · The world, decoded
БГ
CISA

The Zimbra hole went from theoretical to actively exploited in eight days

NVDSecurity

On 13 August the exploitation field for CVE-2026-73570 read one word: none. On 21 August CISA added it to the catalogue of actively exploited vulnerabilities, with a deadline of 24 August. The hole lets an attacker without a password run commands on the mail server.

In short
  • CVE-2026-73570 affects Zimbra Collaboration Suite before 10.1.20, when the zimbra-snmp package is installed with notifications enabled. CVSS 3.1: 8.9.
  • 13 August: published, no confirmed exploitation. 21 August: added to CISA's catalogue of actively exploited vulnerabilities.
  • The remediation deadline is 24 August. The attacker needs no password.
Checked on25 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

On 13 August the exploitation field for CVE-2026-73570 read one word: none. On 21 August the same field said something else.

Zimbra Collaboration Suite is a mail server. Not some exotic thing off to the side, but the machine that actually runs an organisation's mail.

The facts: CVE-2026-73570 affects Zimbra Collaboration Suite before version 10.1.20, when the zimbra-snmp package is installed and SNMP notifications, the protocol for monitoring network equipment, are enabled. The CVSS 3.1 score is 8.9, high. The cause is improper sanitisation of unvalidated input while processing those notifications: an unauthenticated attacker can send a crafted request and run operating system commands as the zimbra user. On 21 August CISA added the number to its catalogue of known exploited vulnerabilities, with a remediation deadline of 24 August. Sources: the NVD record and CISA's KEV catalogue.

Eight days, then three

Eight days from publication to confirmed exploitation. Then three to be ready. Not much. Especially for an organisation that ships server changes once every two weeks.

Eight days between theoretical and used against you. Then three to be ready.

CISA does not say how the hole was used, only that it was. That is all the record says, and that is all I am writing here.

If you run Zimbra and the zimbra-snmp package sits installed with notifications on, update to 10.1.20. Checking which version you are running takes a minute, and it is worth doing before you read any further down this page.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→NVD: CVE-2026-73570→CISA: Known Exploited Vulnerabilities Catalog
Original: https://wearecoded.com/en/articles/zimbra-cve-2026-73570-osem-dni.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news