Active exploitation of the Zimbra CVE-2026-73570 command-injection vulnerability has put internet-facing email servers at immediate risk, according to the US Cybersecurity and Infrastructure Security Agency. CISA added the flaw to its Known Exploited Vulnerabilities catalog and set an August 24 remediation deadline for federal civilian agencies, while Zimbra administrators worldwide are being urged to secure affected systems.

CVE-2026-73570 affects Zimbra Collaboration Suite releases before 10.1.20, according to the National Vulnerability Database and government advisories. Zimbra released version 10.1.20 on July 20 with a fix for the SNMP monitoring component. The vendor notes that older unsupported releases can share vulnerabilities found in supported versions and should be upgraded to a supported release.

The vulnerability is an operating-system command injection caused by inadequate sanitization during SNMP notification processing. An unauthenticated attacker can send specially crafted SMTP requests that execute arbitrary commands with the privileges of the Zimbra user. Exploitation depends on the zimbra-snmp package being installed and SNMP notifications being enabled, limiting exposure to servers with that optional configuration.

CERT Polska first reported that the flaw was being targeted, and CISA subsequently classified it as actively exploited. The Shadowserver Foundation says it began reporting artifacts from probable CVE-2026-73570 compromises on August 20 in collaboration with CERT Polska. BleepingComputer reported on August 24 that Shadowserver had identified more than 270 compromised Zimbra instances while searching for those artifacts.

Administrators should upgrade affected deployments to Zimbra Collaboration Suite 10.1.20 or later and assess exposed servers for evidence of compromise rather than treating patching alone as proof that a system was not breached. CISA directs agencies to follow vendor mitigations and its forensic triage requirements; where mitigations are unavailable, its catalog entry calls for discontinuing use of the product.

Defenders should prioritize internet-facing mail infrastructure, confirm whether the SNMP package and notifications are active, and preserve relevant evidence before remediation. The Canadian Centre for Cyber Security and Singapore's Cyber Security Agency also urged users and administrators to apply the available update, reinforcing the need for rapid patching and post-compromise investigation.