Over 270 Zimbra servers have been compromised by hackers in ongoing attacks that exploit a high-severity vulnerability in the email and collaboration suite. The attacks, which are being tracked as CVE-2026-73570, allow unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
The Zimbra Collaboration Suite (ZCS) is used by hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies. Despite this widespread adoption, however, many Zimbra instances remain unpatched, leaving them vulnerable to attacks that can lead to sensitive data theft and other malicious activity.
The vulnerability in question was patched by Synacor with the release of ZCS version 10.1.20 on July 20. However, CERT Polska, the Polish Computer Emergency Response Team (CERT), first flagged the vulnerability as targeted in the wild last Monday, warning security teams to check their logs for suspicious activity and to patch their systems immediately.
The Cybersecurity and Infrastructure Security Agency (CISA) has also taken notice of the threat, adding it to its KEV catalog and ordering U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days, by August 24. Shadowserver, a threat security watchdog, reported that hundreds of Internet-exposed Zimbra instances have already been breached in attacks exploiting the CVE-2026-73570 flaw.
Zimbra vulnerabilities are often targeted by cybercriminals and state-sponsored hacking groups, who use them to steal emails containing sensitive data from vulnerable servers. In recent years, hackers have exploited Zimbra flaws to breach Ukrainian government servers, U.S. and UK government email accounts, and even NATO-aligned email accounts.
The ease with which attackers can exploit these vulnerabilities is alarming. According to a recent report, once attackers gain valid credentials, they can bypass up to 63% of security controls. This highlights the importance of keeping software up to date and patching vulnerabilities as soon as possible.
In light of this ongoing threat, it’s essential for Zimbra users to take immediate action. Organizations should check their systems for any signs of compromise and apply the latest patches to prevent further attacks. Individuals who use Zimbra should also ensure that their passwords are secure and that they monitor their email accounts for suspicious activity. By taking these precautions, we can reduce the risk of falling victim to these types of attacks and protect our sensitive data from malicious actors.
Source: Bleeping Computer — 2026-08-25