On 13 August the exploitation field for CVE-2026-73570 read one word: none. On 21 August CISA added it to the catalogue of actively exploited vulnerabilities, with a deadline of 24 August. The hole lets an attacker without a password run commands on the mail server.
- CVE-2026-73570 affects Zimbra Collaboration Suite before 10.1.20, when the zimbra-snmp package is installed with notifications enabled. CVSS 3.1: 8.9.
- 13 August: published, no confirmed exploitation. 21 August: added to CISA's catalogue of actively exploited vulnerabilities.
- The remediation deadline is 24 August. The attacker needs no password.
On 13 August the exploitation field for CVE-2026-73570 read one word: none. On 21 August the same field said something else.
Zimbra Collaboration Suite is a mail server. Not some exotic thing off to the side, but the machine that actually runs an organisation's mail.
Eight days, then three
Eight days from publication to confirmed exploitation. Then three to be ready. Not much. Especially for an organisation that ships server changes once every two weeks.
CISA does not say how the hole was used, only that it was. That is all the record says, and that is all I am writing here.
If you run Zimbra and the zimbra-snmp package sits installed with notifications on, update to 10.1.20. Checking which version you are running takes a minute, and it is worth doing before you read any further down this page.