Somewhere, an obscure network-monitoring feature nobody remembers enabling is quietly letting strangers run commands on a mail server. It's the tech equivalent of finding out the spare key you hid under the doormat in 2019 still works.
An SNMP Setting Nobody Thinks About, Now a Front Door
CVE-2026-73570 is a code injection flaw in Zimbra Collaboration Suite that lets an unauthenticated attacker send specially crafted SMTP requests and get arbitrary operating system commands executed as the Zimbra user. It only bites installations with the optional zimbra-snmp package installed and SNMP notifications turned on — but plenty of admins turned that on years ago and never looked back.
Zimbra quietly patched it back in July with version 10.1.20, but Poland's CERT flagged active exploitation in the wild in mid-August, the Shadowserver Foundation has already spotted 274+ compromised instances, and CISA has since added it to its Known Exploited Vulnerabilities catalog — with federal agencies given just three days to remediate. Meanwhile, more than 8,200 unpatched instances are still sitting online.
The Gap Between "Patched" and "Actually Patched"
Here's the uncomfortable truth this story keeps proving: a patch existing and a patch being applied are two very different security postures. Zimbra fixed this over a month before attackers started actively exploiting it — plenty of runway that a lot of organizations simply didn't use.
The real lesson isn't "patch your email server," though obviously do that. It's that any optional feature you enabled once for convenience — SNMP monitoring, a legacy integration, a plugin you forgot exists — is a standing liability until someone actively audits it. Attack surface doesn't shrink on its own.
An unpatched mail server is basically a welcome mat with a USB port. Don't be the 8,200.
If "which optional features are quietly exposed on our servers" is a question nobody at your company can answer confidently, our free security checklist for developers is built exactly for that gap: check it out here.
Source: Help Net Security