Patching the Mail Server Is the First Step. Now Check Whether You Were Already Hit.
Zimbra has fixed an unauthenticated command-injection flaw in its SNMP monitoring component, but CERT Polska is already seeing exploitation. For exposed organisations, the job is no longer only to install an update. It is to determine whether the mail server was used before the update arrived.
Update, 24 August: Shadowserver finds more than 270 probable compromises
Shadowserver’s Compromised Website Report now includes Zimbra installations tagged zimbra-compromised when investigators find artifacts consistent with probable exploitation of CVE-2026-73570. The foundation says the detection was developed with CERT Polska and the tag was first added on 20 August.
BleepingComputer reported on 24 August that Shadowserver had identified more than 270 compromised Zimbra Collaboration Suite instances while hunting for those artifacts. Shadowserver also tracks more than 12,000 internet-exposed Zimbra servers. The exposure figure is not a vulnerability or compromise count, and the 270 instances should not be interpreted as 270 separate organisations.
This materially raises the incident-response threshold. Administrators should not wait for a generic exploitation alert. Affected servers now have a defined compromise-artifact class that Shadowserver is distributing to network owners. Organisations that receive a zimbra-compromised report should treat it as an incident signal, preserve evidence and investigate beyond patch status.
Active exploitation changes the response
CVE-2026-73570 is a remote command-execution vulnerability affecting Zimbra Collaboration before version 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
CERT Polska says the flaw is being actively exploited. An unauthenticated attacker can execute shell commands with the privileges of the zimbra user when SNMP traps are enabled through snmp_notify and the swatchdog service is running. CERT Polska notes that swatchdog is enabled by default in the relevant setup.
This does not mean every Zimbra server is vulnerable. The affected configuration matters. It also does not mean every vulnerable server has been compromised. Active exploitation means administrators need to answer both questions quickly and separately.
CISA has added the flaw to its exploited-vulnerability catalogue
On 21 August 2026, the US Cybersecurity and Infrastructure Security Agency added CVE-2026-73570 to its Known Exploited Vulnerabilities catalogue. The listing independently confirms exploitation and gives affected US federal civilian systems a remediation deadline of 24 August 2026.
The entry also points agencies to the forensic-triage requirements in Binding Operational Directive 26-04. That is operationally important beyond the federal deadline: internet-exposed Zimbra servers that were vulnerable before patching should be checked for compromise rather than treated as safe solely because the update was installed.
Patch first, then assess the period before the patch
Zimbra lists 10.1.20 as the fixed release. Administrators should verify the installed version, confirm whether zimbra-snmp and SNMP notifications are in use, and upgrade without delay.
The update closes the vulnerable path. It cannot remove a web shell, scheduled task, altered account or other persistence created during an earlier intrusion. A server that was exposed while vulnerable should therefore be treated as an incident-response question, not as a completed maintenance task.
CERT Polska published concrete compromise checks
CERT Polska recommends reviewing /var/log/zimbra.log for service-state messages in which attacker-controlled content appears as the service name. The patterns are:
Service status change: <malicious payload> changed from stopped to running
Service status change: <malicious payload> changed from running to stopped
Administrators should also identify files created by the zimbra user during the previous 30 days in these locations:
/opt/zimbra/jetty/webapps//opt/zimbra/jetty_base/webapps//tmp/
Those checks should be widened if retention allows. Attackers may alter timestamps, move files or use existing tools instead of leaving a simple payload in an expected directory. Network telemetry, authentication logs, outbound connections and changes to Zimbra accounts can provide the context that a single filesystem search cannot.
Finding an indicator should trigger containment
If the log patterns or suspicious files are present, responders should preserve evidence, isolate the server where operationally possible and investigate the attacker’s actions. Rebuilding from a known-good state may be safer than attempting to clean a mail platform whose integrity can no longer be established.
Credentials and secrets accessible to the zimbra account should be considered in scope. Review administrative and mailbox activity, rotate relevant credentials, examine trusted integrations and verify that no forwarding rules, delegated access or persistence mechanisms were added.
Mail servers sit at a valuable trust junction. They contain sensitive communications, support password resets and connect to identity, archiving, monitoring and backup systems. A foothold on the server can therefore matter far beyond the vulnerable SNMP component.
The patch closes the flaw, not the incident
CERT Polska’s warning is useful because it does more than repeat a version number. It gives defenders a starting point for deciding whether exploitation happened before they acted.
Upgrade to Zimbra Collaboration 10.1.20 or later, reduce unnecessary exposure and complete the compromise assessment. The operational finish line is not a green patch dashboard. It is confidence that the server was not already used as an entry point.
Sources and further reading
- CERT Polska active-exploitation warning and hunting guidance
- Zimbra security advisories
- BlackTree CVE record
- CISA Known Exploited Vulnerabilities entry and remediation requirement
- Shadowserver Compromised Website Report, last updated 24 August 2026; publication time not stated.
- BleepingComputer: CISA orders urgent patching of actively exploited Zimbra flaw, published 24 August 2026 at 06:45; site timezone not stated.


