The short version: If your North Carolina business still runs its own Zimbra mail server, it may already be running someone else's code. Attackers are actively exploiting CVE-2026-73570, a pre-authentication command-injection flaw rated CVSS 8.9 that lets an unauthenticated attacker run operating-system commands on an unpatched Zimbra Collaboration Suite server, per SOCRadar. Shadowserver counted 155 compromised internet-facing Zimbra instances on August 20 and 274 by August 25, a jump driven by automated tooling, per Help Net Security. The patch shipped in July. The mass exploitation is happening now.
Even if you are not on Zimbra, the question it raises is yours too: who patches the server your whole company emails through?
Key takeaway: The fix, Zimbra 10.1.20, was released on July 20, 2026. CERT Polska reported in-the-wild exploitation around August 18. That is roughly a four-week window between "patch available" and "servers falling," and four weeks is longer than most small NC shops take to notice a security update exists.
Running Zimbra, Exchange, or any on-premise mail server and not sure it is current? Preferred Data Corporation has kept NC businesses' email running securely since 1987. Call (336) 886-3282 or request a mail server security check.
What is CVE-2026-73570 and why is it being exploited now?
CVE-2026-73570 is a pre-authentication remote code execution flaw in Zimbra Collaboration Suite, carrying a CVSS score of 8.9, that lets a remote attacker with no credentials execute commands as the zimbra system user, per SOCRadar. It lives in Zimbra's SNMP notification handling, in the optional zimbra-snmp package, so exploitation requires that component installed and SNMP notifications enabled, which is a non-default configuration. The malicious input arrives over a crafted request but is mishandled inside the SNMP notification path, so simply blocking SNMP at the firewall is not the fix. It affects Zimbra Collaboration before version 10.1.20.
The timeline explains the current surge:
- July 20, 2026: Zimbra ships the fix in ZCS 10.1.20, per Help Net Security.
- Around August 18, 2026: CERT Polska reports the flaw is being exploited in the wild and urges immediate updates and compromise reviews, per Help Net Security.
- August 21, 2026: CISA adds CVE-2026-73570 to its Known Exploited Vulnerabilities catalog, setting a three-day remediation deadline for federal civilian agencies, per CISA.
- August 25, 2026: Shadowserver's compromise count reaches 274 servers, up 77 percent from five days earlier, per Help Net Security.
Quotable definition: A pre-authentication remote code execution flaw means an attacker needs no username, no password, and no click from your staff. Reaching the server over the network is the whole attack. That is why exposed mail servers get hit by automated scanners the moment a working exploit circulates.
Access as the zimbra user is not a minor foothold. That account can read stored mail, harvest credentials, and pivot deeper into the network, so a compromise of the mail server is a compromise of the correspondence itself.
How exposed is a small business, really?
Wider than the compromise count suggests, with one important caveat. Beyond the 274 confirmed break-ins, thousands of Zimbra servers remained unpatched during the exploitation window, though the flaw is only exploitable where the optional zimbra-snmp component is installed and SNMP notifications are enabled, per Help Net Security. That is a narrower set than "every unpatched server," but it is not a set most owners can rule themselves out of without checking. Zimbra is popular precisely with the organizations least equipped to check: small firms, local nonprofits, county and municipal offices, and hosting resellers that stood up on-premise mail years ago to save on per-mailbox fees.
That describes a lot of the Piedmont Triad. A 25-person distributor in Greensboro whose previous IT contractor set up Zimbra in 2019 and moved on. A High Point professional-services firm running its own mail to avoid a per-seat cloud bill. A small manufacturer near Hickory whose mail server was configured once and has not been touched since, because it "just works." None of them get a push notification when a CVE lands.
The self-hosted mail server is rarely a decision anymore. It is an inheritance. Somebody stood it up for a good reason a decade ago, that person left, and the box kept humming, quietly accumulating unpatched CVEs while everyone assumed someone else was watching it. CVE-2026-73570 is what that assumption costs.
Want to know whether your inherited mail server is patched, exposed, or already compromised? Call Preferred Data Corporation at (336) 886-3282 or explore managed cybersecurity.
Patch now, then answer the harder question
The immediate move is not complicated. The harder question is whether you should be in the mail-server business at all. Handle both.
This week, if you run Zimbra:
- Confirm your version. On the server, run
su - zimbra -c "zmcontrol -v"(the flag is a lowercase v; Zimbra CLI options are case-sensitive). Anything before 10.1.20 is vulnerable, per SOCRadar. Update to 10.1.20 or later on an emergency schedule, matching the federal three-day pace, not a "next maintenance window" pace. - Assume compromise until you check. Because exploitation predates most patch cycles, a server exposed in mid-August should be reviewed for signs of intrusion, not merely patched, per Help Net Security. Have whoever runs the box look for unexpected processes running as
zimbra, new accounts, and outbound connections, and apply the indicators CERT Polska published. - Rotate credentials the server touched. Mail, admin, and any service accounts, because a
zimbra-user foothold has had access to them. - Reduce the attack surface. Check whether the risky component is even present with
zmcontrol status; ifsnmpshows up and you do not monitor Zimbra over SNMP, remove it, and restrict who can reach the server from the internet.
Then, the decision:
| Question | Keep self-hosting mail | Move to managed cloud mail |
|---|---|---|
| Who patches a critical CVE in 72 hours? | Your in-house staff, if available | The provider's 24/7 security team |
| Your internet-facing attack surface | Your mail server, always exposed | No mail server for you to expose |
| Cost model | Server, licenses, and your time | Predictable per-mailbox fee |
| Time to notice a new CVE | Whenever someone checks | Handled upstream |
| Where continuity lives | On one box in your closet | Provider redundancy + your backup |
Key takeaway: Cloud email is not automatically safer, and it is not free of its own risks. What it does is move the "patch a critical flaw in three days" race to a vendor that staffs for it around the clock, which a two- or three-person NC IT team simply cannot. For most small manufacturers and firms, that trade is the whole point.
One caution on the cloud side: moving to Microsoft 365 or Google Workspace does not remove your responsibility for backup. The provider keeps the service running; recovering a deleted or ransomware-encrypted mailbox is still on you, which is why a SaaS backup belongs in the migration plan, not after it. That is the honest counterweight to the whole argument: the cloud is not a magic shield, it is a shift in who owns the next critical patch, and it comes with a backup obligation you must not skip.
What Preferred Data Corporation does for NC businesses on this
PDC has provided managed IT, managed cybersecurity, and cloud and email migrations for North Carolina businesses since 1987. For a flaw like CVE-2026-73570, that means:
- Emergency patch and compromise review. We confirm your Zimbra version, apply the fix, and check for the signs of an intrusion that a patch alone does not remove.
- A straight answer on self-hosting. We tell you honestly whether keeping your own mail server still makes sense for your size and staff, rather than defaulting to whatever is already installed.
- A migration that does not lose mail. If moving off makes sense, we plan the cutover to keep history, calendars, and continuity intact, and we build backup into the plan so a cloud mailbox is still recoverable.
For a Greensboro, Winston-Salem, Charlotte, or Raleigh business tired of babysitting a server it inherited, that is the difference between patching a critical flaw in three days and reading about the one that got missed.
Ready to hand off the mail server you inherited? Call (336) 886-3282 or book a mail server review. Preferred Data Corporation, 1208 Eastchester Drive, Suite 131, High Point, NC 27265.
Straight answers for NC business owners
Is my Zimbra server definitely hacked if I have not patched?
Not definitely, but you cannot assume it is clean. Shadowserver confirmed 274 compromised servers by August 25, and thousands more remained unpatched during the exploitation window, per Help Net Security. Because exploitation is automated and pre-authentication, an exposed, unpatched server is a likely target, so review it for intrusion rather than assuming the patch alone is enough.
What version of Zimbra fixes CVE-2026-73570?
Zimbra Collaboration Suite 10.1.20, released July 20, 2026, per SOCRadar. Any version before 10.1.20 is affected. Update on an emergency schedule; CISA gave federal agencies three days, per CISA, and a small business is not less exposed than a federal office.
We do not use SNMP. Are we still at risk?
Possibly. The flaw is in the optional zimbra-snmp package and SNMP notification handling, so a server with that component installed and notifications enabled is exposed even if you never think about SNMP, per SOCRadar. The safe move is to patch to 10.1.20 regardless and disable zimbra-snmp if you do not need it.
Should a small business run its own mail server at all in 2026?
For most small NC firms, the honest answer is no. Self-hosting means you own the race to patch every critical flaw within days, against automated attackers, forever. Managed cloud mail moves that burden to a provider with a full-time security team, at a predictable per-mailbox cost. The exception is a specific compliance or integration need that genuinely requires on-premise mail, and even then it needs a real patching owner.
If we move to Microsoft 365, do we still need backup?
Yes. Microsoft keeps the service available, but recovering a deleted, corrupted, or ransomware-hit mailbox is your responsibility under the shared-responsibility model. A third-party SaaS backup is what makes a cloud mailbox recoverable, and it should be part of the migration, not an afterthought.
How fast can PDC help if we think we are already compromised?
Call (336) 886-3282 and we treat it as an incident, not a ticket. For NC businesses, PDC works on-site across the Piedmont Triad, Greensboro, High Point, Charlotte, and Raleigh within the 200-mile service radius, starting with containment and a compromise review before the cleanup and, if it makes sense, the migration.
Related Resources
- Managed Cybersecurity for NC Businesses - Emergency patching and compromise review
- Cloud Solutions and Email Migration - Moving off a self-hosted mail server safely
- SaaS and Data Backup - Recoverable mailboxes after a cloud migration
- Email Migration to Microsoft 365 in North Carolina
- Exchange Server OWA Zero-Day: NC SMB Defense
- On-Prem SharePoint Exploitation: Migrate or Defend
- Contact Preferred Data Corporation - Mail server security check for NC businesses