Attackers have compromised at least 274 Zimbra servers, while thousands of unpatched systems remain potentially exposed.
The Shadowserver Foundation said it identified 274 compromised internet-facing Zimbra instances on Aug. 22, up from 155 two days earlier, in attacks exploiting CVE-2026-73570. The nonprofit also found at least 8,200 unpatched Zimbra systems, although not all are necessarily vulnerable because the flaw requires a specific, non-default configuration.
“Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22,” Shadowserver said.
The attacks were first flagged by Poland’s CERT Polska in mid-August, which warned administrators to look for signs such as unexpected Zimbra service restarts and suspicious files created by the Zimbra user in Zimbra’s web application and temporary directories.
How the vulnerability works
CVE-2026-73570 is a command-injection flaw in Zimbra Collaboration Suite’s SNMP monitoring component. It can allow an unauthenticated attacker to execute operating system commands remotely as the Zimbra user when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Attackers can trigger the flaw through specially crafted SMTP requests.
Synacor disclosed the vulnerability June 26 and released a fix in ZCS 10.1.20 on July 20. CISA later added the flaw to its Known Exploited Vulnerabilities catalog and required U.S. federal civilian agencies to apply vendor mitigations or stop using affected products by Aug. 24.
The bigger risk sits in the mail server
A compromised Zimbra server presents a more serious problem than an ordinary vulnerable application because it sits at the center of an organization’s communications.
Attackers able to execute commands on the server could potentially gain access to information and functions handled by the mail platform. The sources have not established whether any data was stolen from the 274 compromised systems, however, and no threat actor has publicly claimed responsibility for the campaign.
That uncertainty makes compromise checks just as important as installing the patch. Updating an already breached server does not by itself remove an attacker’s access or undo changes made during the intrusion.
Why organizations should act now
Zimbra has repeatedly attracted both cybercriminals and state-linked groups, including attacks associated with APT28, APT29 and Winter Vivern.
Organizations running Zimbra should identify every internet-facing deployment, install the vendor-fixed release for its software branch, verify whether the optional SNMP component and notifications are enabled, and investigate CERT Polska’s compromise indicators. Because patching does not remove persistence or reverse changes made during an intrusion, administrators that find suspicious artifacts should treat the server as potentially breached and begin incident-response procedures.
Read more: Russian-linked hackers have also exploited a separate Zimbra vulnerability to target government mail servers, highlighting the platform’s continued appeal to sophisticated threat groups.





