Attackers Compromise 270+ Zimbra Servers Using SNMP Flaw

Threat actors have compromised more than 270 Zimbra Collaboration Suite (ZCS) servers in ongoing remote code execution attacks targeting a high-severity vulnerability tracked as CVE-2026-73570. The flaw stems from a command injection weakness in the SNMP monitoring component, and it allows unauthenticated attackers to gain remote code execution when SNMP notifications are enabled. Synacor patched the issue with the release of ZCS version 10.1.20 on July 20, but many organizations have not yet updated their systems.

CERT Polska first flagged the vulnerability as actively exploited in the wild and urged security teams to review logs for signs of compromise, such as unexpected Zimbra service restarts and files created by the zimbra user in web application and temporary directories. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog and requires U.S. Federal Civilian Executive Branch agencies to patch within three days. Security watchdog Shadowserver reports 274 compromised instances as of August 22, along with at least 8,200 still-unpatched instances, though not all are necessarily exploitable because the vulnerable configuration is non-default.

Zimbra vulnerabilities are a frequent target for both cybercriminals and state-sponsored hacking groups, which have used them repeatedly in recent years to steal sensitive emails from vulnerable servers. In March, Seqrite Labs researchers observed APT28, a Russian military intelligence-linked group, abusing a stored cross-site scripting flaw in Zimbra to breach Ukrainian government servers. U.S. and UK cyber agencies have also warned about Russian intelligence services exploiting Zimbra weaknesses, underscoring the urgency for organizations to apply the latest patches promptly.

Read More at the original source →