CVE-2026-73570: Compromises through Zimbra SNMP-flaw are spreading

Last Updated: August 24th, 2026

What’s Happening

According to the Shadowserver Foundation, compromises of instances of the collaboration software and email platform Zimbra through abuse of CVE-2026-73570 are spreading.

The vulnerability has been added to the CISA KEV-list on August 21th, the current numbers by Shadowserver count close to 275 compromised instances worldwide, with instances in the United States being affected the most so far (41).

Additionally, there are around 8200 instances running a vulnerable version reachable from the public Internet. That does not mean those are actually vulnerable because exploitation of CVE-2026-73570 requires a non-standard configuration.

Actions

An update that fixes the vulnerability has been available since July 20th. Because exploitation of compromised Zimbra-instances has been the bread and butter of various state sponsored threat actors I would emphatically recommend patching and thoroughly investigating potentially vulnerable instances that you are responsible for.

3 Likes

Fantastic post! Has anyone seen anything useful as indicators? Ideally behavioral, but sources of exploitation would be solid too. If Shadowserver published them, I missed it.