Over 270 Zimbra servers breached in ongoing attacks

 

Over 270 Zimbra servers breached in ongoing attacks

More than 270 Zimbra Collaboration Suite (ZCS) servers have been compromised in ongoing attacks. The vulnerability, tracked as CVE-2026-73570, allows attackers to remotely run code without logging in. It affects Zimbra’s SNMP monitoring component when SNMP notifications are enabled.

Zimbra developer Synacor fixed the flaw in version 10.1.20, released on July 20. However, security researchers say attackers are already using the vulnerability against exposed servers.

Cybersecurity group Shadowserver reported seeing hundreds of Zimbra systems that had been breached using the flaw. CERT Polska previously warned organizations to check their logs for signs of attacks, including unexpected Zimbra service restarts and new files in Zimbra and temporary directories.

“Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22,” The Shadowserver said. “We also see at least 8200 CVE-2026-73570 unpatched instances (this does not mean exploitable as the vuln is in a non default config).”

In March, Seqrite Labs researchers reported that the Russian military hackers APT28 exploited a stored cross-site scripting (XSS) flaw in Zimbra to breach Ukrainian government servers.

In October 2024, US and UK cyber agencies warned that Russian Foreign Intelligence Service hackers, known as APT29, Midnight Blizzard and Cozy Bear, had also compromised Zimbra servers. The attackers used a Zimbra flaw that had previously been exploited to steal email account credentials.

Another Russian-linked group, tracked as Winter Vivern (TA473, UAC-0114, or TAG-70), has exploited a reflected XSS vulnerability in Zimbra to steal emails from NATO-aligned accounts through targeted attacks on Zimbra webmail portals.

In February 2022, a likely Chinese threat actor, tracked as as TEMP_Heretic, exploited a Zimbra zero-day flaw in attacks on European governments and media.

That being said, security teams using Zimbra are strongly advised to update to the latest version and review their systems for signs of compromise.


Back to the list