Over 270 Zimbra servers compromised in ongoing RCE attacks
Threat actors have compromised more than 270 Zimbra instances by exploiting CVE-2026-73570, a command injection flaw in the SNMP monitoring component. The vulnerability allows unauthenticated remote code execution when SNMP notifications are enabled, and was patched in ZCS 10.1.20. CERT Polska and CISA have warned about active exploitation, with Shadowserver reporting hundreds of breached servers.
The attacks leverage a command injection flaw in Zimbra’s SNMP monitoring component, which is only exploitable when SNMP notifications are enabled—a non-default configuration. Shadowserver’s scans identified over 8,200 unpatched instances, though not all are necessarily vulnerable. CERT Polska advised administrators to inspect logs for unexpected Zimbra service restarts and suspicious files in specific webapp and temporary directories. Zimbra has been a frequent target for both cybercriminals and state-sponsored groups, with past incidents involving Russian APT28, APT29, and Winter Vivern campaigns stealing credentials and emails from government and NATO-aligned targets.
The breach of hundreds of Zimbra servers could disrupt email services for organizations relying on the suite, potentially exposing sensitive communications from government agencies and businesses. If attackers leverage stolen credentials or maintain persistence, they may conduct further espionage or data theft. The rapid CISA mandate for federal patching underscores the risk, but many unpatched instances remain, suggesting that smaller entities without dedicated security teams may face prolonged exposure. The incident may also prompt broader scrutiny of default configurations in widely deployed collaboration software.