HomeSecurityZimbra: 274 installations have already been compromised via RCE

Zimbra: 274 installations have already been compromised via RCE

A new cyberattack campaign is underway targeting Zimbra Collaboration Suite (ZCS) installations, as attackers exploit a serious vulnerability to remotely execute malicious code. According to the latest figures, at least 274 installations accessible via the Internet have already been compromised, which significantly increases the concern for organizations that are still using outdated versions of the platform.

Zimbra

Email infrastructure in the spotlight

Zimbra Collaboration Suite is a widely used email and collaboration platform used by businesses, organizations, and government agencies in many countries. Its widespread presence makes it an attractive target for cybercriminals, as a successful server compromise can provide access to messages, accounts, and other data.

See also: CVE-2026-21962: Critical Oracle WebLogic vulnerability being exploited

This attack is based on the CVE-2026-73570 vulnerability , which is related to a command injection vulnerability in the SNMP monitoring component . The exploitation is possible when the relevant SNMP notifications are enabled and, according to available evidence, no prior authentication of the attacker is required.

Synacor , which manages the development of Zimbra, fixed the issue with ZCS version 10.1.20 , which was released on July 20. However, the availability of an update does not automatically mean that all systems are protected, as today's image demonstrates .

274 servers compromised in a few days

CERT Polska was among the first to detect active exploitation of the vulnerability on the Internet. The warning to administrators was clear: organizations should immediately check the logs of Zimbra servers and look for signs that could be linked to an attack.

Suspicious indications include unexpected restarts of the Zimbra service, as well as the creation of unknown files by the “zimbra” user. Particular attention should be paid to the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ and /tmp/ directories, where files related to the breach may have been stored.

Zimbra: 274 installations have already been compromised via RCE

Shadowserver , it identified 274 compromised installations during scans for exploit traces.

See also: Insecure deserialization in NLTK: CVE-2026-78683

Thousands of systems remain unupdated

Even more worrying is the fact that the same service identified at least 8,200 Zimbra installations that had not installed the update for CVE-2026-73570. This, of course, does not mean that all of them are automatically vulnerable, as the attack requires specific configuration and the problematic feature is not enabled by default.

However, the number is a significant indicator of risk. An unpatched server exposed to the Internet can become an easy entry point, especially when administrators are unaware of what services are enabled in their environment.

Why Zimbra is a timeless goal

Attacks against Zimbra servers are not a new phenomenon. In previous years, different cybercriminal groups and state-backed actors have exploited vulnerabilities in the platform to access emails and credentials.

In March, researchers at Seqrite Labs attributed a stored XSS exploit targeting Ukrainian government servers to Russian hackers from APT28 . Earlier, in 2024, US and British cybersecurity agencies had warned of attacks by APT29 , also known as Midnight Blizzard or Cozy Bear, against Zimbra infrastructure.

At the same time, the Winter Vivern group has been linked to a reflected XSS exploit in Zimbra webmail gateways, aiming to steal emails from NATO-related accounts.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: TranslatePress Vulnerability: Critical Privilege Escalation in WordPress

Zimbra: 274 installations have already been compromised via RCE

What administrators should do immediately

Organizations using Zimbra should immediately install the patch, check whether SNMP and related alerts are enabled, and look for suspicious changes in log files.

Additionally, it is important to examine user accounts, server processes, and recently created files. In case of indications of a breach, simply installing the update is not enough: a full system investigation, changing credentials, and checking for possible lateral movement of the attacker are required.

The addition of CVE-2026-73570 to Known Exploited Vulnerabilities (KEV) list confirms that this is now an active threat and not just a theoretical risk. For any organization relying on Zimbra, speed of response could prove crucial in preventing a much more serious breach.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS