Hackers breached over 270 Zimbra servers in ongoing attacks
Reported exploitedZimbra Collaboration SuiteOur summary
Over 270 internet-facing instances of Zimbra Collaboration Suite have been compromised through active exploitation of CVE-2026-73570, a high-severity remote code execution vulnerability. Synacor addressed this flaw, which involves command injection in the SNMP component when notifications are enabled, by releasing version 10.1.20. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog following reports from CERT Polska and Shadowserver, prompting urgent patching directives for federal agencies.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.