Cyber Attackers Breach Hundreds of Email Servers Using Unpatched Vulnerability
A sophisticated cyber attack is unfolding on a massive scale, with over 270 email servers compromised using an unpatched vulnerability in the Zimbra Collaboration Suite (ZCS). The attack has been ongoing for weeks, and experts warn that hundreds of thousands of other servers remain vulnerable to exploitation. The victims include not only businesses but also government agencies worldwide.
The vulnerability, known as CVE-2026-73570, was patched by Synacor in July with the release of ZCS version 10.1.20. However, many organizations have yet to apply the fix, leaving their email servers exposed to attack. The exploit allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
CERT Polska, the Polish Computer Emergency Response Team (CERT), first flagged the vulnerability as targeted in the wild last Monday, warning security teams to check their logs for suspicious activity and files created by user zimbra. The Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its KEV catalog and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.
Shadowserver, a threat security watchdog, reported that it spotted hundreds of Internet-exposed Zimbra instances that have already been breached in attacks exploiting the CVE-2026-73570 flaw. “Zimbra compromises associated with CVE-2026-73570 exploitation are spreading,” Shadowserver warned. “274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22.”
The Zimbra vulnerability is not new, and it has been frequently exploited by cybercriminals and state-sponsored hacking groups in recent years. In March, Seqrite Labs researchers spotted APT28 Russian military intelligence hackers abusing a stored cross-site scripting (XSS) Zimbra vulnerability to breach Ukrainian government servers.
The ease of exploitation has significant implications for organizations that have yet to patch their systems. Once attackers gain valid credentials, prevention scores drop sharply, and only 37% of their actions are blocked. This highlights the importance of applying timely patches and maintaining up-to-date security measures.
For readers who use Zimbra or any other email collaboration suite, this is a stark reminder that even seemingly minor vulnerabilities can have devastating consequences when exploited on a large scale. It’s essential to prioritize patch management and ensure that all systems are regularly updated with the latest security fixes.
Source: Bleeping Computer — 2026-08-25