Poland's CERT, then the US agency CISA, confirmed active
exploitation of a critical flaw in Zimbra Collaboration Suite, email software
used by companies and government agencies. Over 12,000 servers
are exposed online, at least 270 are reportedly already
compromised.
⚠️ This case file sits outside the
Laboratory's usual scope. Our other case files document personal data
leaks. This one documents an actively exploited software flaw — no personal
data is directly named here. We include it because an unpatched corporate mail
server flaw can cascade into exposing an entire organization's correspondence —
and because attributing the facts deserves the same rigor as any hacker's
claim.
The numbers, all officially confirmed
Jul 20
Date the patch was released, in Zimbra version
10.1.20.
Zimbra, via BleepingComputer.
12,000+
Zimbra servers directly exposed on the internet, per
researcher counts.
BleepingComputer.
270+
Instances confirmed compromised, already identified at
time of publication.
BleepingComputer.
3 days
Remediation deadline CISA imposed on US federal civilian
agencies, starting August 21.
CISA, KEV catalog.
Timeline
CONFIRMED
July 20, 2026
Zimbra releases version 10.1.20, fixing
CVE-2026-73570: an OS command injection in the SNMP monitoring component,
exploitable without authentication when SNMP notifications and the
swatchdog service are enabled.
CONFIRMED
August 18, 2026
Poland's CERT (CERT Polska) is first to flag active
exploitation of the flaw on unpatched servers — nearly a month after the
patch became available.
CONFIRMED
August 21, 2026
CISA confirms Poland's CERT alert and adds the flaw to
its Known Exploited Vulnerabilities (KEV) catalog, imposing a 3-day
remediation deadline on US federal agencies.
CONFIRMED
August 24, 2026
Specialist security press (BleepingComputer,
SecurityWeek) confirms the tally: over 12,000 servers exposed online, at
least 270 instances already compromised.
⚙️The technical mechanism, plainly
The flaw sits in the server's monitoring function (SNMP), not in the mail
handling itself. An attacker who needs no credentials at all can make the
server run arbitrary system commands — effectively remote administrator-level
control. On a mail server, that potentially opens access to every mailbox it
hosts, not just one account.
Source: technical analysis, via SecurityAffairs.
What this means for you
Directly: nothing for you to do yourself, this flaw isn't fixed on the user
side. If your work, university, or nonprofit email runs on Zimbra, the question
belongs to your organization's administrator: is version 10.1.20 installed?
Indirectly, this case file illustrates a recurring mechanism across this
Laboratory — unpatched software remains the most common entry point for an
intrusion, well ahead of individual negligence.
🔒 If you administer or use a Zimbra mailbox in a
professional setting, check the installed version today: 10.1.20 fixes the
flaw, any earlier version remains exposed.
Frequently asked questions
What is Zimbra, and why is this flaw serious?
Business email software. The flaw allows remote command execution with no
credentials at all — the maximum severity for this class of software.
Is my personal email account affected?
Only if your mail is hosted on an unpatched Zimbra server — rarely the
case for a consumer address.
Does a patch exist?
Yes, since July 20, 2026 (version 10.1.20).
📌 Last checked: August 25, 2026.
Verifiable information to report: contact@egidio.app.
Cite this pageEgidio — The Threat Laboratory, "Zimbra: critical flaw exploited, 270+ servers already breached," egidio.app/en/laboratoire/zimbra-critical-flaw-active-exploitation/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.