[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f64GiRwbcrFX62-8pexFyb-dZraUMxqOQVa7zxsNRK0c":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"02aba13a-2af2-40ee-ad9a-c684b4c5b7c5","Hackers breached over 270 Zimbra servers in ongoing attacks","hackers-breached-over-270-zimbra-servers-in-ongoing-attacks-2f69a5","Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]","Threat actors are actively exploiting a high-severity remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite (ZCS), leading to the compromise of over 270 servers. The flaw, which allows unauthenticated attackers to execute code via command injection in the SNMP monitoring component, was patched by Synacor in version 10.1.20. CISA has added it to its KEV catalog, mandating patching for US federal agencies, while CERT Polska and Shadowserver have reported widespread exploitation and numerous unpatched instances.","Hackers exploit Zimbra RCE flaw, compromising over 270 servers.","Hackers breached over 270 Zimbra servers in ongoing attacks By Sergiu Gatlan August 25, 2026 08:04 AM 0 Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide. Synacor patched the security flaw (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of ZCS version 10.1.20 on July 20. CERT Polska, the Polish Computer Emergency Response Team (CERT), first flagged the vulnerability as targeted in the wild last Monday, when it also warned security teams to check their logs for suspicious activity, including the Zimbra service restarting unexpectedly, and for files created in the \u002Fopt\u002Fzimbra\u002Fjetty\u002Fwebapps\u002F, \u002Fopt\u002Fzimbra\u002Fjetty_base\u002Fwebapps\u002F, and \u002Ftmp\u002F folders by user zimbra over the last 30 days. The Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its KEV catalog following CERT Polska's warning and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days, by August 24. On Monday, threat security watchdog Shadowserver reported that it spotted hundreds of Internet-exposed Zimbra instances that have already been breached in attacks exploiting the CVE-2026-73570 flaw. Map of compromised Zimbra instances (Shadowserver) \"Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22,\" Shadowserver warned. \"We also see at least 8200 CVE-2026-73570 unpatched instances (this does not mean exploitable as the vuln is in a non default config).\" Zimbra vulnerabilities are often targeted by cybercriminals and state-sponsored hacking groups, and have been frequently exploited to steal emails containing sensitive data from vulnerable servers in recent years. Most recently, in March, Seqrite Labs researchers spotted APT28 Russian military intelligence hackers abusing a stored cross-site scripting (XSS) Zimbra vulnerability to breach Ukrainian government servers. U.S. and UK cyber agencies also warned in October 2024 that Russian Foreign Intelligence Service hackers (tracked as APT29, Midnight Blizzard, and Cozy Bear) compromised Zimbra servers using a ZCS flaw previously exploited to steal email account credentials. Russian Winter Vivern cyber spies also exploited a reflected Cross-Site Scripting (XSS) vulnerability to steal emails from NATO-aligned email accounts in attacks targeting Zimbra webmail portals. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: CISA orders urgent patching of actively exploited Zimbra flawCritical Zimbra RCE flaw now actively exploited in attacksOne threat actor responsible for 83% of recent Ivanti RCE attacksMicrosoft patches max severity code execution, privilege escalation flawsCritical RCE flaw in Windows IKE Extension now actively exploited","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-breached-over-270-zimbra-servers-in-ongoing-attacks\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F08\u002F25\u002FZimbra.jpg","2026-08-25T12:04:02+00:00","2026-08-25T14:00:50.143769+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"Zimbra Collaboration Suite","product",{"name":22,"type":23},"Synacor","vendor",{"name":25,"type":26},"APT28","threat_actor",{"name":28,"type":26},"APT29",{"name":30,"type":26},"Midnight Blizzard",{"name":32,"type":26},"Cozy Bear","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,46],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52,56,59,60,61,62],{"type":53,"value":54,"context":55},"cve","CVE-2026-73570","Zimbra Collaboration Suite (ZCS) vulnerability exploited in attacks.",{"type":57,"value":25,"context":58},"malware","Threat actor group previously linked to exploiting Zimbra vulnerabilities.",{"type":57,"value":28,"context":58},{"type":57,"value":30,"context":58},{"type":57,"value":32,"context":58},{"type":57,"value":63,"context":58},"Vivern"]