Hackers Breach 270 Zimbra Servers in Ongoing Attacks
New Zimbra server attacks have compromised more than 270 systems worldwide. Attackers exploit a serious vulnerability in Zimbra Collaboration Suite.
The flaw carries the identifier CVE-2026-73570. It allows unauthenticated attackers to execute commands remotely on vulnerable servers. Synacor fixed the vulnerability in Zimbra version 10.1.20. The company released that update on July 20.
However, many exposed systems remain vulnerable. Security researchers have already found hundreds of compromised servers connected to the attacks. CERT Polska first warned about active exploitation last week. The agency urged administrators to inspect their systems for suspicious activity.
Security Teams Face Urgent Risks
Shadowserver later identified 274 compromised Zimbra instances. Its scans also found more than 8,200 unpatched systems exposed online.
The vulnerable feature involves Zimbra’s SNMP monitoring component. Attackers can exploit a command injection weakness when SNMP notifications remain enabled.
Meanwhile, the US cybersecurity agency CISA added the flaw to its Known Exploited Vulnerabilities catalog. Federal agencies received an August 24 deadline for applying security updates. Administrators should therefore check their Zimbra servers immediately. They should also review logs for unexpected service restarts and unusual files.
Examine Specific Security Security teams can examine specific Zimbra directories for suspicious files. These locations include web application folders and temporary storage areas.
Zimbra has attracted cybercriminals and state-backed groups for years. Attackers often target the platform because email servers can contain valuable business information.
For example, Russian hacking groups have previously exploited Zimbra weaknesses. Those campaigns targeted government organizations and NATO-aligned accounts.
The latest activity highlights the risks of delaying security updates. Internet-facing email systems can become attractive targets soon after vulnerabilities become public. Organizations should confirm their Zimbra version and apply the latest security fixes. They should also investigate signs of compromise before restoring normal operations. The growing number of breaches shows why rapid patching matters. Unpatched collaboration servers can expose sensitive communications and organizational data.