CVE-2026-73570 exploited on 274 Zimbra servers for email archive theft
CVE-2026-73570 enabled remote command execution on Zimbra servers with specific SNMP settings. 274 instances were compromised with email theft observed. Patch lag and conditional exposure created a measurable window for exploitation.
Synacor released a patch on July 20 for the command injection flaw in the SNMP notification path. Microsoft observed two scanning campaigns that first validated exploits via HTTP and DNS callbacks, then deployed JSP web shells, reverse shells, and memory-resident tools. Shadowserver telemetry recorded 274 compromised instances, with total exposed servers dropping from 19,000 to 10,000 post-patch.
The vulnerability requires the optional zimbra-snmp package and enabled notifications, limiting the attack surface. Data shows rapid automated payload delivery followed by hands-on credential harvesting and archive exfiltration across multiple sectors and regions. Prior Zimbra incidents, including CVE-2019-9670 and CVE-2022-27925, followed similar patterns of delayed disclosure after patch availability.
Operationally, organizations must audit SNMP configuration, apply patches within days, and monitor for anomalous archive transfers. Remaining 10,000 instances continue to face scanning pressure, increasing breach probability until full remediation.
Shadowserver: vulnerable Zimbra instances will fall below 4,000 by November 2026 if current patching rate holds.
Sources (2)
- [1]Primary Source(https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/)
- [2]Supporting Source(https://www.microsoft.com/en-us/security/blog/2026/09/zimbra-exploitation-report)