logo

Hackers breached over 270 Zimbra servers in ongoing attacks

ID: 8ec82e12-4f98-5109-9f85-03d44e1be1d2

STIX ID: report--8ec82e12-4f98-5109-9f85-03d44e1be1d2

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Sergiu Gatlan

...
...

A critical command-injection vulnerability in Zimbra Collaboration Suite's SNMP monitoring (CVE-2026-73570) is being actively exploited in the wild; Synacor released ZCS 10.1.20 to patch the issue, but scans found at least 274 compromised instances and some 8,200 unpatched installations. CERT Polska and CISA issued warnings and emergency guidance (including KEV listing and federal patching orders), with defenders urged to check for suspicious restarts and files created by the zimbra user in webapps and /tmp folders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.