Hackers breached over 270 Zimbra servers in ongoing attacks

Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have compromised more than 270 Zimbra Collaboration Suite instances by exploiting CVE-2026-73570, a high-severity remote code execution flaw in the SNMP monitoring component. Synacor patched the issue in ZCS 10.1.20, while CERT Polska, CISA, and Shadowserver warned of active exploitation and widespread unpatched systems. #Zimbra #CVE-2026-73570 #Synacor #CERTPolska #CISA #Shadowserver

Keypoints

  • Over 270 Zimbra instances have been compromised in active exploitation.
  • CVE-2026-73570 allows unauthenticated remote code execution through command injection.
  • The flaw affects the SNMP monitoring component when SNMP notifications are enabled.
  • Synacor fixed the issue in ZCS version 10.1.20 on July 20.
  • CERT Polska, CISA, and Shadowserver have warned about in-the-wild attacks and many unpatched systems.

Read More: https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/