Hundreds of Zimbra Instances Compromised in Active Exploitation of Critical RCE Flaw
Threat actors are actively exploiting a high-severity remote code execution (RCE) vulnerability in **Zimbra Collaboration Suite (ZCS)**, leading to the compromise of over 270 instances globally. The flaw, tracked as **CVE-2026-73570**, allows unauthenticated attackers to gain remote code execution, posing a significant risk to the hundreds of millions of users and organizations reliant on ZCS.
Threat actors have successfully compromised over 270 **Zimbra** instances through attacks targeting a critical remote code execution (RCE) vulnerability within the **Zimbra Collaboration Suite (ZCS)**.
**ZCS** is a widely used email and collaboration platform, serving thousands of businesses and hundreds of government agencies worldwide.
### The Vulnerability: CVE-2026-73570
The security flaw, identified as **CVE-2026-73570**, stems from a command injection weakness in the **SNMP** monitoring component. When **SNMP** notifications are enabled, this vulnerability allows unauthenticated attackers to achieve remote code execution. **Synacor**, the developer of **Zimbra**, addressed the flaw with the release of **ZCS version 10.1.20** on July 20.
### Widespread Warnings and Urgent Calls to Action
The **Polish Computer Emergency Response Team (CERT Polska)** was the first to flag the active exploitation of this vulnerability, urging security teams to scrutinize logs for suspicious activities such as unexpected **Zimbra** service restarts or the creation of new files in `/opt/zimbra/jetty/webapps/`, `/opt/zimbra/jetty_base/webapps/`, and `/tmp/` folders by the `zimbra` user within the last 30 days.
Following this alert, the **Cybersecurity and Infrastructure Security Agency (CISA)** promptly added **CVE-2026-73570** to its **Known Exploited Vulnerabilities (KEV) Catalog**. **CISA** mandated that U.S. Federal Civilian Executive Branch (FCEB) agencies patch their systems by August 24, emphasizing the urgency of the situation.
### Hundreds of Instances Already Breached
Security watchdog **Shadowserver** confirmed on Monday that it has identified hundreds of Internet-exposed **Zimbra** instances that have already been breached via the **CVE-2026-73570** exploit.

"**Zimbra** compromises associated with **CVE-2026-73570** exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22," **Shadowserver** reported. The organization also noted at least 8,200 unpatched instances, though not all may be immediately exploitable due to the vulnerability's reliance on a non-default configuration.
### A Recurring Target for Threat Actors
**Zimbra** vulnerabilities have consistently been a favored target for both cybercriminals and state-sponsored hacking groups, often exploited to exfiltrate sensitive email data from compromised servers. Recent examples include:
* In March, **Seqrite Labs** researchers observed **APT28**, a Russian military intelligence group, leveraging a stored cross-site scripting (**XSS**) **Zimbra** vulnerability to infiltrate Ukrainian government servers.
* In October 2024, U.S. and UK cyber agencies warned that Russian Foreign Intelligence Service hackers (**APT29**, also known as **Midnight Blizzard** or **Cozy Bear**) compromised **Zimbra** servers using a previously exploited **ZCS** flaw to steal email account credentials.
* Russian cyber spies, dubbed **Winter Vivern**, exploited a reflected **Cross-Site Scripting (XSS)** vulnerability to steal emails from NATO-aligned accounts via **Zimbra** webmail portals.