
Menace actors have already compromised over 270 Zimbra cases in distant code execution assaults focusing on a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
The ZCS e mail and collaboration suite is utilized by lots of of hundreds of thousands of individuals and organizations, together with 1000’s of companies and lots of of presidency companies worldwide.
Synacor patched the safety flaw (tracked as CVE-2026-73570), which permits unauthenticated attackers to achieve code execution remotely by exploiting a command injection weak spot within the SNMP monitoring element when SNMP notifications are enabled, with the discharge of ZCS version 10.1.20 on July 20.
CERT Polska, the Polish Laptop Emergency Response Group (CERT), first flagged the vulnerability as focused within the wild final Monday, when it additionally warned safety groups to examine their logs for suspicious exercise, together with the Zimbra service restarting unexpectedly, and for information created within the /choose/zimbra/jetty/webapps/, /choose/zimbra/jetty_base/webapps/, and /tmp/ folders by person zimbra during the last 30 days.
The Cybersecurity and Infrastructure Safety Company (CISA) additionally added the flaw to its KEV catalog following CERT Polska’s warning and ordered U.S. Federal Civilian Government Department (FCEB) companies to patch their programs inside three days, by August 24.
On Monday, risk safety watchdog Shadowserver reported that it noticed lots of of Web-exposed Zimbra cases which have already been breached in assaults exploiting the CVE-2026-73570 flaw.

“Zimbra compromises related to CVE-2026-73570 exploitation are spreading. 274 cases seen compromised in our scans for exploitation artifacts on 2026-08-22,” Shadowserver warned.
“We additionally see at the very least 8200 CVE-2026-73570 unpatched cases (this doesn’t imply exploitable because the vuln is in a non default config).”
Zimbra vulnerabilities are sometimes focused by cybercriminals and state-sponsored hacking teams, and have been regularly exploited to steal emails containing delicate information from susceptible servers lately.
Most just lately, in March, Seqrite Labs researchers noticed APT28 Russian army intelligence hackers abusing a saved cross-site scripting (XSS) Zimbra vulnerability to breach Ukrainian government servers.
U.S. and UK cyber companies additionally warned in October 2024 that Russian Overseas Intelligence Service hackers (tracked as APT29, Midnight Blizzard, and Cozy Bear) compromised Zimbra servers utilizing a ZCS flaw beforehand exploited to steal email account credentials.
Russian Winter Vivern cyber spies additionally exploited a mirrored Cross-Web site Scripting (XSS) vulnerability to steal emails from NATO-aligned e mail accounts in assaults focusing on Zimbra webmail portals.
Total prevention scores can disguise what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses approach by approach throughout 338 million simulations run in buyer manufacturing environments.

