← Back to overview

Threat actors have actively compromised over 270 Zimbra Collaboration Suite (ZCS) servers by exploiting a high-severity remote code execution vulnerability. The attacks are ongoing, suggesting a widespread and coordinated campaign targeting ZCS instances. The vulnerability allows attackers to execute arbitrary code remotely on affected servers. The scale of compromise indicates that many organizations have not yet patched their Zimbra installations. Zimbra is widely used in enterprise and government environments, making this a significant security incident. Organizations running ZCS are urged to apply patches immediately to prevent further breaches.

Technical details

CVE-2026-73570 is a high-severity command injection vulnerability in the SNMP monitoring component of Zimbra Collaboration Suite (ZCS). It allows unauthenticated remote attackers to achieve remote code execution (RCE) when SNMP notifications are enabled on the target server. This is a non-default configuration, meaning not all exposed instances are necessarily exploitable. As of August 22, 2026, Shadowserver reported 274 confirmed compromised instances and over 8,200 unpatched internet-exposed instances. The vulnerability was patched by Synacor in ZCS version 10.1.20 released on July 20, 2026. CERT Polska first flagged active exploitation the week of August 18, 2026, and CISA added it to the KEV catalog on August 21, 2026.

Mitigation steps

1. Immediately upgrade Zimbra Collaboration Suite to version 10.1.20 or later. 2. U.S. FCEB agencies were ordered by CISA to patch by August 24, 2026. 3. Check server logs for suspicious activity, particularly unexpected Zimbra service restarts. 4. Inspect for unauthorized files created in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ by user zimbra over the last 30 days. 5. If SNMP notifications are not required, consider disabling SNMP notifications to reduce attack surface. 6. Monitor Shadowserver and CISA KEV catalog for updates on exploitation activity.

Affected products

  • Zimbra Collaboration Suite (ZCS) - versions prior to 10.1.20

Related CVE's

  • CVE-2026-73570

Related threat actors

  • APT28 (Russian GRU military intelligence)
  • APT29 (Midnight Blizzard / Cozy Bear - Russian Foreign Intelligence Service SVR)
  • Winter Vivern

IOC's

Unexpected restart of the Zimbra service, Files created in /opt/zimbra/jetty/webapps/ by user zimbra within the last 30 days, Files created in /opt/zimbra/jetty_base/webapps/ by user zimbra within the last 30 days, Files created in /tmp/ by user zimbra within the last 30 days

Categories

  • Data Breach & Exfiltration
  • Email & Messaging
  • Enterprise Applications
  • Zero-Day Vulnerabilities