Threat actors have compromised more than 270 Zimbra Collaboration Suite (ZCS) instances in ongoing remote code execution attacks targeting a high-severity vulnerability. The flaw, tracked as CVE-2026-73570, allows unauthenticated attackers to achieve code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled. Synacor, the company behind ZCS, patched the issue with the release of ZCS version 10.1.20 on July 20. The suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide.

The Polish Computer Emergency Response Team, known as CERT Polska, first flagged the vulnerability as being exploited in the wild last Monday. CERT Polska also advised security teams to review their logs for suspicious activity, including unexpected restarts of the Zimbra service and files created in specific directories by the zimbra user over the prior 30 days. Following that warning, the Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog. CISA also ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days, by August 24.

On Monday, the threat security watchdog Shadowserver reported that it had detected hundreds of Internet-exposed Zimbra instances already breached through attacks exploiting CVE-2026-73570. Shadowserver said that 274 instances were seen compromised in scans for exploitation artifacts on August 22. The group also observed at least 8,200 unpatched instances, though it noted that this number does not necessarily mean all are exploitable since the vulnerability is in a non-default configuration.

Zimbra vulnerabilities have frequently been targeted by both cybercriminals and state-sponsored hacking groups in recent years, often to steal emails containing sensitive data. In March, Seqrite Labs researchers spotted APT28, a Russian military intelligence hacking group, abusing a stored cross-site scripting (XSS) Zimbra vulnerability to breach Ukrainian government servers. That incident highlights the ongoing interest from nation-state actors in exploiting Zimbra installations.

U.S. and UK cyber agencies warned in October 2024 that Russian Foreign Intelligence Service hackers, tracked as APT29, Midnight Blizzard, and Cozy Bear, had compromised Zimbra servers using a ZCS flaw previously exploited to steal email account credentials. Additionally, the Russian Winter Vivern cyber espionage group exploited a reflected XSS vulnerability to steal emails from NATO-aligned email accounts in attacks targeting Zimbra webmail portals. These incidents underscore the persistent threat landscape facing organizations that rely on Zimbra for their email and collaboration needs.

More cybersecurity news from TechManNews.