Published · yesterdayBuild2 min read
Zimbra's patch-to-exploitation gap is either zero days or seven, and nobody wrote it down
Zimbra shipped the fix for CVE-2026-73570 on July 20, a Monday, and CERT Polska flagged live attacks on a Monday. Two days is an inference, not a record.
Written for builders.See today for builders

What happened
- CERT Polska warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite.
- The Zimbra security team released version 10.1.20 on July 20 to patch CVE-2026-73570.
- CVE-2026-73570 lets an unauthenticated attacker gain remote code execution through a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled; improper sanitization during SNMP notification processing means specially crafted SMTP requests may execute arbitrary operating system commands as the zimbra user.
- On Monday, the Polish CERT team reported that threat actors are now exploiting CVE-2026-73570 in attacks.
- Shadowserver tracks over 12,100 Zimbra servers exposed online, with 4,382 in Europe and 4,492 in Asia.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
The two-day figure is not in the source material. What BleepingComputer supplies is a dated fix and an undated warning: version 10.1.20 on July 20, and exploitation reported by CERT Polska "on Monday" [2][4]. July 20, 2026 was itself a Monday [15]. The record therefore allows zero days or seven, depending on which Monday the Polish team meant, and two is not one of the options [16].
Either reading sits inside a normal change-approval cycle, so the interesting number in the notice is a different one: 30. CERT Polska tells admins to look back 30 days for files created by user zimbra in the two jetty webapps directories and /tmp, and for the Zimbra service restarting by itself [7]. That lookback is wider than either candidate gap between fix and warning [18], which is a statement about what the responders think they might find rather than about the patch.
The exposure side is softer than the headline count suggests. The injection only reaches a server with SNMP notifications enabled, arriving as crafted SMTP requests and running as the zimbra user [3], so Shadowserver's 12,100 internet-facing hosts bound the reachable population rather than describe the vulnerable one [5]. Of those, 4,382 are in Europe and 4,492 in Asia, leaving roughly 3,200 elsewhere [17], and none of the three figures separates honeypots or already-patched boxes [6].
Citrix's week is the same problem read forward. Rapid7 says there is no sign anyone is exploiting CVE-2026-19490, the CVSS 9.3 NetScaler authentication bypass patched on Wednesday, and still recommends emergency patching because Citrix products tend to see exploitation quickly [9][10][11]. Zimbra is the evidence behind that reasoning: reflected XSS used by Winter Vivern against NATO-aligned mailboxes in February 2023 [12], a US and UK warning about APT29 in October 2024 [13], and APT28 activity against Ukrainian government servers in March [14]. The lesson holds whether the answer was zero days or seven.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CERT Polska warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite.
- [2]
The Zimbra security team released version 10.1.20 on July 20 to patch CVE-2026-73570.
ReportedView cited source - [3]
CVE-2026-73570 lets an unauthenticated attacker gain remote code execution through a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled; improper sanitization during SNMP notification processing means specially crafted SMTP requests may execute arbitrary operating system commands as the zimbra user.
ReportedView cited source - [4]
On Monday, the Polish CERT team reported that threat actors are now exploiting CVE-2026-73570 in attacks.
- [5]
Shadowserver tracks over 12,100 Zimbra servers exposed online, with 4,382 in Europe and 4,492 in Asia.
- [6]
There is no information on how many of the exposed Zimbra servers are honeypots or have already been patched against CVE-2026-73570.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comyesterdayCritical Zimbra RCE flaw now actively exploited in attacks
- securityweek.comyesterdayExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler - SecurityWeek
Additional citations
- CERT Polska, reported by BleepingComputer
- CERT Polska
- Shadowserver
- Rapid7
- Seqrite Labs

