Hackers have breached more than 200 internet-facing Zimbra email servers worldwide by exploiting an unauthenticated remote-code-execution flaw
Attackers are actively exploiting CVE-2026-73570, a command-injection flaw in Zimbra Collaboration Suite's SNMP component, patched July 20 but under active attack since mid-August. Shadowserver counted 267 breached servers as of August 24, down from a peak of 274, with over 8,200 more still unpatched. Per BleepingComputer / The Hacker News.
A high-severity vulnerability in Zimbra Collaboration Suite, CVE-2026-73570 (CVSS 8.9), lets an unauthenticated attacker send crafted SMTP requests to execute operating system commands on servers running the optional zimbra-snmp package with SNMP notifications enabled. Zimbra patched the flaw on July 20, 2026 with ZCS version 10.1.20. CERT Polska first flagged active in-the-wild exploitation in mid-August, and the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on August 21, ordering federal civilian agencies to patch by August 24. The Shadowserver Foundation tracked compromised internet-facing Zimbra instances peaking at 274 on August 22 and standing at 267 as of August 24, out of roughly 12,100 reachable Zimbra servers online. At least 8,200 additional unpatched instances were also found, though not all are necessarily exploitable since the flaw requires a non-default configuration. Sources: BleepingComputer, The Hacker News.