Threat actors have actively compromised over 270 Zimbra Collaboration Suite (ZCS) servers by exploiting a high-severity remote code execution vulnerability. The attacks are ongoing, suggesting a widespread and coordinated campaign targeting ZCS instances. The vulnerability allows attackers to execute arbitrary code remotely on affected servers. The scale of compromise indicates that many organizations have not yet patched their Zimbra installations. Zimbra is widely used in enterprise and government environments, making this a significant security incident. Organizations running ZCS are urged to apply patches immediately to prevent further breaches.
CVE-2026-73570 is a high-severity command injection vulnerability in the SNMP monitoring component of Zimbra Collaboration Suite (ZCS). It allows unauthenticated remote attackers to achieve remote code execution (RCE) when SNMP notifications are enabled on the target server. This is a non-default configuration, meaning not all exposed instances are necessarily exploitable. As of August 22, 2026, Shadowserver reported 274 confirmed compromised instances and over 8,200 unpatched internet-exposed instances. The vulnerability was patched by Synacor in ZCS version 10.1.20 released on July 20, 2026. CERT Polska first flagged active exploitation the week of August 18, 2026, and CISA added it to the KEV catalog on August 21, 2026.
1. Immediately upgrade Zimbra Collaboration Suite to version 10.1.20 or later. 2. U.S. FCEB agencies were ordered by CISA to patch by August 24, 2026. 3. Check server logs for suspicious activity, particularly unexpected Zimbra service restarts. 4. Inspect for unauthorized files created in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ by user zimbra over the last 30 days. 5. If SNMP notifications are not required, consider disabling SNMP notifications to reduce attack surface. 6. Monitor Shadowserver and CISA KEV catalog for updates on exploitation activity.
Unexpected restart of the Zimbra service, Files created in /opt/zimbra/jetty/webapps/ by user zimbra within the last 30 days, Files created in /opt/zimbra/jetty_base/webapps/ by user zimbra within the last 30 days, Files created in /tmp/ by user zimbra within the last 30 days