CVE Tools

Hackers breached over 270 Zimbra servers in ongoing attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedZimbra Collaboration Suite

Our summary

Over 270 internet-facing instances of Zimbra Collaboration Suite have been compromised through active exploitation of CVE-2026-73570, a high-severity remote code execution vulnerability. Synacor addressed this flaw, which involves command injection in the SNMP component when notifications are enabled, by releasing version 10.1.20. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog following reports from CERT Polska and Shadowserver, prompting urgent patching directives for federal agencies.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store