Patching a Zimbra Collaboration Suite server against CVE-2026-73570 no longer closes the exposure window. The Shadowserver Foundation had already flagged 155 compromised internet-facing Zimbra instances by August 20, and that count kept climbing through the week, with roughly 8,200 unpatched instances still reachable from the internet as of this run. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 21, giving federal agencies until August 24 to remediate.
The vulnerability is a command injection flaw in how Zimbra’s SNMP notification handling processes untrusted input, letting an unauthenticated attacker send crafted requests that execute operating system commands as the Zimbra user. Synacor, which maintains Zimbra, shipped a permanent fix in version 10.1.20, released July 20, following an earlier advisory on June 26. That means the vulnerable window was public and patchable for weeks before mass exploitation became visible in Shadowserver’s telemetry, which is exactly the gap attackers used.
Zimbra has landed on CISA’s KEV catalog repeatedly across the past several years, spanning command injection, cross-site scripting and server-side request forgery bugs in the same product line. That is not a coincidence worth shrugging off. For a security leader, a mail and collaboration platform that keeps reappearing on the exploited-vulnerabilities list is a signal to treat its patch cadence as a standing risk item, not a one-off fire drill: track every Zimbra instance in inventory against the current release, not just against whichever CVE made news this week, and assume that “patched now” does not mean “was never compromised” without a forensic check of the exposure window. CISA’s newer directive requires exactly that forensic triage for its highest-risk tier, and Zimbra’s repeat appearances on the KEV list are a case study in why.
Related coverage: One Keycloak Flaw Bypassed Every Password Reset.