Back to BlogEmail Security Insights

Zimbra flaw CVE-2026-73570 is under attack: what should small businesses do?

StopSpoofingMe TeamPublished 6 min read

If your business uses Zimbra email, whether you run it yourself or a provider runs it for you, make sure it's on version 10.1.20 or later now. On August 21, CISA said attackers are actively exploiting CVE-2026-73570, a Zimbra flaw that can let someone with no account run commands on the mail server.

Key takeaways

  • On August 21, 2026, CISA added CVE-2026-73570, an OS command injection flaw in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities catalog, based on evidence of active exploitation.
  • According to CISA, an unauthenticated attacker could send specially crafted SMTP requests that may result in running operating system commands as the Zimbra user.
  • Zimbra released version 10.1.20 on July 20, 2026, with a fix for a command injection vulnerability in its SNMP monitoring component when SNMP notifications are enabled.
  • A hacked mail server can send email as your domain that passes SPF, DKIM and DMARC, because it's your own authorized server.
  • Upgrade, ask your email provider what it runs, rotate credentials if you were exposed, and watch your DMARC reports.

What happened?

CISA confirms attacks

On Friday, August 21, 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. CISA describes it as an OS command injection vulnerability in Zimbra Collaboration Suite that could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

In plain terms, someone with no account on your system could send the server specially crafted traffic over SMTP, the protocol mail servers use to accept email from the internet, and run commands on it. CISA gave US federal civilian agencies until August 24, three days after listing, to deal with it.

What did Zimbra release in July?

Zimbra released version 10.1.20 on July 20, 2026. According to Zimbra, the release includes a fix for a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. SNMP is a standard way for servers to report their health to monitoring tools.

Don't read the SNMP detail as a reason to wait. With CISA confirming active exploitation, the safe course is to run 10.1.20 or later and to have Zimbra or your provider confirm that your version includes the fix for CVE-2026-73570.

Date (2026) What happened
July 20 Zimbra releases 10.1.20 with a fix for a command injection flaw in SNMP monitoring
July 23 CISA, NSA, FBI and partners warn about a separate, espionage-driven Zimbra webmail campaign
August 21 CISA adds CVE-2026-73570 to its KEV catalog, citing active exploitation
August 24 CISA's deadline for US federal civilian agencies

Not Zimbra's first warning this summer

On July 23, CISA, NSA, FBI and partner agencies warned that a Russia-linked group they call LAUNDRY BEAR was exploiting a different Zimbra flaw. It fired when a user simply opened a malicious email in unpatched Zimbra webmail, and was used to steal the last 90 days of mail, credentials and two-factor authentication tokens. Different bug, same lesson: an unpatched mail server is a prime target.

Why does this matter for your business?

A hacked mail server can send email "as you" and pass authentication

SPF tells the world which servers may send mail for your domain. DKIM signs your outgoing mail with a key only you should hold. DMARC checks that those results line up with the domain in the From address. Your own mail server is, by design, on that approved list, and if it signs your mail, it also has access to your DKIM signing key.

So if an attacker takes over the server, the phishing or fake-invoice emails they send from it can pass SPF, DKIM and DMARC as your domain. To the receiving server's authentication checks, they look like your real mail. An enforced DMARC policy stops outsiders forging your domain; it can't tell you from someone who has taken over your server. Keeping that server patched is part of protecting your domain.

Your mailboxes are a fraud playbook

A mail server holds every conversation about invoices, vendors and payments. Anyone who can read it learns who you pay, when, and how you ask, which is exactly what they need for a convincing business email compromise (BEC) attempt against you, your customers or your suppliers.

You may be running Zimbra without knowing it

If your email comes from a web host or a local IT provider rather than Microsoft 365 or Google Workspace, you may not know what software runs it. It's worth a quick question.

What should you do now?

  1. Find out whether Zimbra is involved. If you host your own mail, check the software and version. If someone else hosts it, ask them directly whether they run Zimbra and which version.
  2. Upgrade to Zimbra 10.1.20 or later now. If you're on an older release line, ask Zimbra or your provider which update fixes CVE-2026-73570 for your version.
  3. Don't swap the upgrade for a settings change. Zimbra's description ties its July fix to SNMP notifications, but the fix it has published is the upgrade. If you truly can't upgrade right away, ask Zimbra support or your provider whether an interim workaround applies to your setup.
  4. Assume an exposed, unpatched server may already be compromised. Upgrading closes the hole but doesn't remove an intruder who's already in. Have the server checked for signs of compromise before you trust it again.
  5. Rotate credentials if there's any doubt. Change administrator and user passwords and, if the server signs mail, generate a new DKIM key and publish it under a new selector.
  6. Read your DMARC aggregate reports. They summarize which sources sent mail using your domain and whether it passed. A sudden jump in daily volume from your own server's IP address deserves a look. Our free scanner shows whether your DMARC record asks for these reports.
  7. Keep every mail system on a patch schedule. The same discipline applies to Exchange; see our rundown of Microsoft's August Exchange and Outlook updates.
  8. Revisit whether to self-host at all. For many small businesses, a managed email platform takes server patching off the to-do list. Our email security services team can help you weigh the options, or call (818) 574-8240.

Frequently asked questions

We don't run our own mail server. Are we affected?

Possibly not, but check. This flaw affects Zimbra Collaboration Suite servers, so businesses whose mail runs entirely on Microsoft 365 or Google Workspace aren't running the affected software. If a web host or IT provider supplies your email, ask whether it uses Zimbra and whether it has installed version 10.1.20 or later. Get the answer in writing if you can.

How can a hacked mail server send email that passes DMARC?

DMARC checks whether a message's From domain matches a domain that passed SPF or DKIM. Your own mail server is authorized in your SPF record and may hold your DKIM signing key, so mail it sends passes those checks, whoever is actually operating it. An enforced DMARC policy stops outsiders forging your domain; it can't detect an attacker using your own infrastructure.

What is CISA's Known Exploited Vulnerabilities catalog?

It's CISA's list of vulnerabilities with evidence of active exploitation. CISA added CVE-2026-73570 on August 21, 2026 and set an August 24 due date for US federal civilian agencies. Private businesses aren't bound by those deadlines, but a KEV listing is a strong signal to treat a patch as urgent rather than routine.

What should we ask our email hosting provider?

Ask what mail server software they run, whether it's affected by CVE-2026-73570, when they installed Zimbra 10.1.20 or later if they use Zimbra, and whether they've checked for signs of compromise. Also ask how, and how quickly, they would tell you if your mail system were breached.

Sources

  1. CISA — CISA Adds One Known Exploited Vulnerability to Catalog (August 21, 2026)
  2. CISA — Known Exploited Vulnerabilities Catalog: CVE-2026-73570 (entry added August 21, 2026)
  3. Zimbra — Patch Release Update: Zimbra 10.1.20 (July 2026)
  4. Zimbra — Zimbra Releases/10.1.20 (release notes, undated)
  5. CISA — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite (AA26-204A) (July 23, 2026)
  6. The Hacker News — Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes (July 2026)
  7. Microsoft Learn — Set up DMARC to validate the From address domain for cloud senders (reference documentation, undated)

Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.

Related Topics

zimbra cve-2026-73570zimbra 10.1.20 security updatezimbra snmp command injectioncisa known exploited vulnerabilities zimbrahacked mail server send email as youself-hosted email security small businessdmarc reports compromised mail server

Ready to Secure Your Email?

Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.