Protect.Computer
NEWS

CISA demands 3-day fix for exploited Zimbra RCE flaw

· 1 min read · Network safety Malicious byte
CISA demands 3-day fix for exploited Zimbra RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has added a remote code execution flaw in Zimbra Collaboration Suite to its Known Exploited Vulnerabilities catalog and ordered U.S. government agencies to patch within three days. The vulnerability, tracked as CVE-2026-73570, allows an unauthenticated attacker to execute arbitrary operating system commands on the mail server by sending specially crafted SMTP requests to the SNMP monitoring component — but only when SNMP notifications are enabled on the target system.

Zimbra shipped a fix in version 10.1.20 on July 20. CERT Polska first flagged active exploitation last week, and threat intelligence firm Shadowserver has since identified over 270 compromised Zimbra instances while scanning for exploitation artifacts. With more than 12,000 Zimbra servers exposed on the internet, organizations running older releases face immediate risk.

How to check if you’re affected

Affected versions include all Zimbra Collaboration Suite releases older than 10.1.20. Log in to your Zimbra administration console and check the installed version under About Zimbra. If you are running a version older than 10.1.20, apply the patch immediately. If patching is not immediately possible, disable SNMP notifications in your Zimbra configuration to remove the attack surface until you can upgrade.

Sources

Related reading