MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-08-25 · via BleepingComputer

Over 270 Zimbra servers compromised in ongoing RCE attacks

Threat actors have compromised more than 270 Zimbra instances by exploiting CVE-2026-73570, a command injection flaw in the SNMP monitoring component. The vulnerability allows unauthenticated remote code execution when SNMP notifications are enabled, and was patched in ZCS 10.1.20. CERT Polska and CISA have warned about active exploitation, with Shadowserver reporting hundreds of breached servers.

Expanded Detail

The attacks leverage a command injection flaw in Zimbra’s SNMP monitoring component, which is only exploitable when SNMP notifications are enabled—a non-default configuration. Shadowserver’s scans identified over 8,200 unpatched instances, though not all are necessarily vulnerable. CERT Polska advised administrators to inspect logs for unexpected Zimbra service restarts and suspicious files in specific webapp and temporary directories. Zimbra has been a frequent target for both cybercriminals and state-sponsored groups, with past incidents involving Russian APT28, APT29, and Winter Vivern campaigns stealing credentials and emails from government and NATO-aligned targets.

Context

The breach of hundreds of Zimbra servers could disrupt email services for organizations relying on the suite, potentially exposing sensitive communications from government agencies and businesses. If attackers leverage stolen credentials or maintain persistence, they may conduct further espionage or data theft. The rapid CISA mandate for federal patching underscores the risk, but many unpatched instances remain, suggesting that smaller entities without dedicated security teams may face prolonged exposure. The incident may also prompt broader scrutiny of default configurations in widely deployed collaboration software.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
SonicWall SMA1000 vulnerability exploited shortly after patch · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers breached over 270 Zimbra servers in ongoing attacks.” Browse more stories.