274 Zimbra Servers Compromised as 8,200 Remain Unpatched

Attackers exploited CVE-2026-73570 to compromise 274 Zimbra servers, while 8,200 systems remain unpatched. Learn what administrators should check.

Aug 26, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Attackers have compromised at least 274 Zimbra servers, while thousands of unpatched systems remain potentially exposed.

The Shadowserver Foundation said it identified 274 compromised internet-facing Zimbra instances on Aug. 22, up from 155 two days earlier, in attacks exploiting CVE-2026-73570. The nonprofit also found at least 8,200 unpatched Zimbra systems, although not all are necessarily vulnerable because the flaw requires a specific, non-default configuration.

“Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22,” Shadowserver said.

The attacks were first flagged by Poland’s CERT Polska in mid-August, which warned administrators to look for signs such as unexpected Zimbra service restarts and suspicious files created by the Zimbra user in Zimbra’s web application and temporary directories.

How the vulnerability works

CVE-2026-73570 is a command-injection flaw in Zimbra Collaboration Suite’s SNMP monitoring component. It can allow an unauthenticated attacker to execute operating system commands remotely as the Zimbra user when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Attackers can trigger the flaw through specially crafted SMTP requests.

Synacor disclosed the vulnerability June 26 and released a fix in ZCS 10.1.20 on July 20. CISA later added the flaw to its Known Exploited Vulnerabilities catalog and required U.S. federal civilian agencies to apply vendor mitigations or stop using affected products by Aug. 24.

The bigger risk sits in the mail server

A compromised Zimbra server presents a more serious problem than an ordinary vulnerable application because it sits at the center of an organization’s communications.

Attackers able to execute commands on the server could potentially gain access to information and functions handled by the mail platform. The sources have not established whether any data was stolen from the 274 compromised systems, however, and no threat actor has publicly claimed responsibility for the campaign.

That uncertainty makes compromise checks just as important as installing the patch. Updating an already breached server does not by itself remove an attacker’s access or undo changes made during the intrusion.

Advertisement

Why organizations should act now

Zimbra has repeatedly attracted both cybercriminals and state-linked groups, including attacks associated with APT28, APT29 and Winter Vivern.

Organizations running Zimbra should identify every internet-facing deployment, install the vendor-fixed release for its software branch, verify whether the optional SNMP component and notifications are enabled, and investigate CERT Polska’s compromise indicators. Because patching does not remove persistence or reverse changes made during an intrusion, administrators that find suspicious artifacts should treat the server as potentially breached and begin incident-response procedures.

Read more: Russian-linked hackers have also exploited a separate Zimbra vulnerability to target government mail servers, highlighting the platform’s continued appeal to sophisticated threat groups.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.