preloader

· · digital-security devops zimbra email cve vulnerability-management patch-management cert-polska europe poland

Poland’s National CERT Just Confirmed Attackers Are Already Inside Zimbra Mail Servers

Source: Security Affairs

A patch that has existed for a month is not a warning anymore, it is a deadline that already passed.

An email server that will run your commands for a stranger

CVE-2026-73570 is a command injection vulnerability, CVSS 8.9, in how Zimbra Collaboration Suite processes SNMP trap notifications. On servers where the optional zimbra-snmp package is installed, SNMP notifications are enabled through the snmp_notify parameter, and the swatchdog monitoring service is running, which it is by default, an unauthenticated attacker can send a specially crafted request that gets executed as an operating system command running as the zimbra user. No login, no social engineering, just a malformed request hitting a service most administrators never think about because they did not knowingly turn it on.

The fix predates the warning by a month

Zimbra shipped version 10.1.20 on 20 July, closing the hole. CERT Polska’s Alert 145/2026, issued in mid-August, confirms attackers are now actively exploiting the flaw in the wild, which means the gap between “patch available” and “attackers using it” has closed. Shadowserver’s internet-wide scan puts more than 12,100 Zimbra servers still exposed online, and the largest concentration by region is in Europe, ahead of Asia. If your organisation runs Zimbra for mail and has not confirmed you are on 10.1.20 or later, this is not a routine maintenance item anymore.

Why the SNMP angle catches teams off guard

Most patch triage focuses on the mail protocols a server obviously exposes: SMTP, IMAP, the web client. SNMP monitoring is easy to forget precisely because it is not the reason anyone deployed the server in the first place, and swatchdog running by default means a server can be exposed through this path without an administrator ever having deliberately configured SNMP for anything. That mismatch between what a team thinks is exposed and what is actually reachable is exactly the gap attackers scan for at internet scale.

What to do this week

Confirm your Zimbra version is 10.1.20 or newer. If you cannot patch immediately, disable snmp_notify and stop the swatchdog service as an interim mitigation, and check mail server logs for command execution patterns tied to SNMP notification handling around the disclosure window. Under NIS2, an actively exploited, unauthenticated RCE sitting unpatched a month after a fix shipped is exactly the kind of gap regulators expect to see documented and closed, not discovered during an incident.

If you need help confirming your mail infrastructure is patched, auditing what services are actually exposed versus what you assume is exposed, or responding to a suspected Zimbra compromise, contact Excello Digital. We help European organisations close the gap between “we deployed it” and “we know exactly what it exposes.”

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!