Over 270 Zimbra Servers Compromised in Exploitation of Critical CVE-2026-73570 Flaw
Threat actors have compromised at least 274 Zimbra Collaboration Suite (ZCS) instances using remote code execution attacks targeting a high-severity vulnerability in the platform.
Zimbra Collaboration Suite is an email and collaboration platform used by hundreds of millions of people worldwide, including organizations, businesses, and government agencies.
The vulnerability, tracked as CVE-2026-73570, allows unauthenticated attackers to remotely execute code by exploiting a command injection flaw in Zimbra’s SNMP monitoring component when SNMP notifications are enabled.
Synacor addressed the security issue in Zimbra Collaboration Suite version 10.1.20, released on July 20, 2026.
CERT Polska, Poland’s Computer Emergency Response Team, first warned last week that attackers were exploiting CVE-2026-73570 in the wild. Security teams observed suspicious activity, including unexpected Zimbra service restarts and unauthorized access to directories such as /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
CERT Polska advised Zimbra administrators to review their logs for suspicious activity, including recently created files and unexpected changes within these directories during the previous 30 days.
The Cybersecurity and Infrastructure Security Agency (CISA) subsequently added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog.
Following the listing, CISA directed U.S. Federal Civilian Executive Branch (FCEB) agencies to patch affected systems by August 24, 2026.
On Monday, internet-monitoring organization Shadowserver reported that hundreds of internet-exposed Zimbra servers had already been compromised through attacks exploiting the vulnerability.

“The Zimbra breach related to the CVE-2026-73570 exploit is growing. A scan of exploit artifacts on August 22, 2026, confirmed that 274 instances were compromised,” Shadowserver warned.
Shadowserver also identified at least 8,200 unpatched Zimbra instances. However, the organization noted that CVE-2026-73570 affects a non-default configuration, meaning that not every unpatched system is necessarily exploitable.
Zimbra vulnerabilities are frequently targeted by cybercriminals and state-sponsored hacking groups. Previous attacks have used flaws in ZCS to steal email messages, credentials, and other sensitive information from vulnerable servers.
In March, Seqrite Labs researchers reported that APT28, a Russian military intelligence-linked hacking group, was exploiting a stored cross-site scripting (XSS) vulnerability in Zimbra to compromise Ukrainian government servers.
In October 2024, U.S. and U.K. cybersecurity agencies warned that Russian Foreign Intelligence Service hackers, tracked as APT29, Midnight Blizzard, and Cozy Bear, had compromised Zimbra servers using a vulnerability previously exploited to steal email account credentials.
Russian cyberespionage group Winter Vivern has also exploited a reflected cross-site scripting (XSS) vulnerability in the Zimbra webmail portal to steal emails from NATO-related accounts.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




