Hundreds of servers running Zimbra Collaboration Suite have already been compromised through Zimbra CVE-2026-73570 attacks, with threat intelligence watchdog Shadowserver reporting 274 breached instances in scans conducted on 22 August 2026. The flaw in question carries a IONIX-assessed CVSS score of 8.9, placing it firmly in the high-severity bracket.

The vulnerability sits in the SNMP monitoring component of Zimbra Collaboration Suite (ZCS). When SNMP notifications are enabled, an unauthenticated attacker can exploit a command injection weakness to achieve remote code execution, without needing any credentials. Synacor patched the flaw, tracked as CVE-2026-73570, with the release of ZCS version 10.1.20 on 20 July 2026.

From Patch to Active Exploitation in Weeks

CERT Polska, Poland’s national Computer Emergency Response Team, was the first to flag the vulnerability as being actively targeted in the wild. Alongside the warning, CERT Polska advised security teams to inspect their logs for tell-tale indicators of compromise: unexpected Zimbra service restarts and files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ directories by the zimbra user over the preceding 30 days.

The Cybersecurity and Infrastructure Security Agency (CISA) followed up by adding CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog on 21 August 2026, according to The Hacker News. CISA simultaneously ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days, setting a deadline of 24 August 2026.

The speed of CISA’s response reflects how quickly the situation deteriorated. By the time the KEV listing went live, exploitation was already well under way.

Zimbra CVE-2026-73570 Attacks: The Infection Count

Shadowserver’s 22 August scans found 274 compromised instances. By 24 August, that figure had shifted to 267, suggesting some administrators had cleaned and remediated affected systems, though the overall picture remains grim. The United States accounted for the largest national share, with 46 infected instances identified, according to The Hacker News.

Shadowserver also counted at least 8,200 unpatched instances still exposed on the internet, though the organisation was careful to note that being unpatched does not automatically mean exploitable: the vulnerability only activates when SNMP notifications are enabled, which is not the default configuration. Still, 8,200 is a large pool from which attackers can work, and the non-default status of the feature has historically not deterred determined threat actors from probing at scale.

The exploitation mechanics here are worth dwelling on. Remote code execution without authentication, through a component that many administrators may not actively monitor, is exactly the kind of foothold that leads to prolonged, quiet access. Once inside, defenders face an uphill battle: across 338 million simulations, only 37% of attacker actions using valid credentials were blocked, underlining how quickly post-access activity can outpace detection.

A Familiar Target for State-Sponsored Groups

Zimbra’s history as an exploitation target is well-documented. In March 2026, Seqrite Labs researchers observed APT28 Russian military intelligence hackers abusing a stored cross-site scripting (XSS) Zimbra vulnerability to breach Ukrainian government servers. Before that, U.S. and UK cyber agencies warned in October 2024 that hackers tracked as APT29, Midnight Blizzard, and Cozy Bear had compromised Zimbra servers using a ZCS flaw that had previously been used to steal email account credentials. Russian Winter Vivern cyber spies separately exploited a reflected XSS vulnerability to steal emails from NATO-aligned accounts via Zimbra webmail portals.

The pattern is consistent: Zimbra vulnerabilities attract both financially motivated cybercriminals and state-sponsored actors, because the platform is used by hundreds of millions of people and organisations globally, including thousands of businesses and hundreds of government agencies. Email access, once gained, tends to be rich in sensitive material.

Administrators who have not yet applied the ZCS 10.1.20 patch should treat Shadowserver‘s public tally of exposed instances as motivation enough: with over 8,200 unpatched servers still internet-facing and 267 already confirmed compromised, the window for a clean remediation is narrowing with each day the patch goes unapplied.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version