Active exploitation of the Zimbra vulnerability CVE-2026-73570 has left at least 274 Collaboration Suite instances showing compromise artifacts, according to an August 25 report by BleepingComputer citing Shadowserver Foundation scans. The activity targets an operating system command injection flaw in the email platform and can provide remote code execution without authentication when a specific optional monitoring configuration is present.

Zimbra fixed the flaw in Collaboration Suite version 10.1.20, released July 20. The vendor describes CVE-2026-73570 as a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. CERT Polska disclosed active exploitation on August 17, and CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring covered US federal agencies to remediate it.

CERT Polska said exploitation is possible on instances where SNMP traps are enabled through the snmp_notify parameter and the swatchdog service is running. An unauthenticated attacker can cause arbitrary shell commands to execute with the privileges of the zimbra service account. Because the vulnerable feature is not enabled in every deployment, the number of unpatched internet-facing servers does not equal the number that can be exploited.

Shadowserver reported finding 274 compromised instances in scans for exploitation artifacts on August 22 and at least 8,200 unpatched instances. BleepingComputer reported that observed post-exploitation activity included deployment of web shells and other malicious components. The scan totals are a measured exposure snapshot rather than a count of every affected or breached server.

Administrators should update affected deployments to Zimbra Collaboration Suite 10.1.20 or later. CERT Polska also recommends reviewing /var/log/zimbra.log for unexpected service status changes and checking for files created by the zimbra user during the previous 30 days in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/. Systems showing suspicious artifacts require incident-response review, not only patch installation.

Defenders should identify internet-facing Zimbra servers, confirm whether SNMP notifications are enabled, and prioritize the vendor update. Log retention and file-integrity evidence should be preserved before cleanup so responders can determine the extent of access. CISA guidance for known exploited vulnerabilities calls for applying vendor mitigations or discontinuing affected products when mitigations are unavailable.