On August 21, CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog after Poland's national CERT confirmed active exploitation. The flaw is an unauthenticated remote code execution vulnerability in Zimbra Collaboration Suite, rated High severity with a CVSS score of 8.9. It affects installations where SNMP trap notifications are enabled through the snmp_notify parameter and the swatchdog service is running, a configuration that is enabled by default in many deployments. An attacker who finds an exposed, unpatched server can send a specially crafted request and execute arbitrary shell commands as the zimbra user, no login and no stolen password required. Zimbra fixed the issue on July 20 in version 10.1.20, but CERT Polska's advisory this week confirms attackers are actively hunting for servers that have not yet been updated.
This is worth a small firm's attention because Zimbra is a common, lower cost alternative to Microsoft 365 for hosting business email, and some solo and small Florida practices, or the IT providers who support them, run it without realizing it sits on this list. A mail server is not just another piece of infrastructure. It is where privileged attorney client communications, calendar detail on client meetings, and years of case correspondence actually live. Successful exploitation lets an attacker plant a web shell, read or exfiltrate mailboxes, and quietly establish persistence on the server, all without ever needing a single set of stolen credentials.
Florida Bar Rule 4-1.6 requires attorneys to make reasonable efforts to prevent unauthorized access to client information, and an internet facing mail server running a version with a known, actively exploited remote code execution flaw is difficult to square with that obligation once a patch has been publicly available for a month. Recommendation 25-1 calls for documented cybersecurity assessments precisely so a firm has an actual record of which systems run what software and whether they are current, rather than an assumption that someone else is handling it.
Three things worth doing this week. First, confirm whether your firm or your IT provider runs Zimbra Collaboration Suite for email, and if so, verify the version is 10.1.20 or newer immediately. Second, if you cannot patch right away, check whether SNMP trap notifications are enabled through the snmp_notify setting and disable that feature until the update is applied, since it is the specific configuration this exploit relies on. Third, ask whoever manages the server to review the Zimbra logs for unexpected service status changes, an unfamiliar service switching between running and stopped, which can be a sign the flaw has already been used against you.
This is precisely the kind of gap ArisGate exists to close for solo and small Florida law firms, keeping the software behind your firm's email current and watching for exactly this kind of exploitation before it reaches a client's mailbox. If you cannot say with certainty what your mail server is running or when it was last patched, that is worth thirty minutes of your time this week. Schedule a free security audit with ArisGate and get a clear answer.