HomeCyber AttacksHackers Breach Over 270 Zimbra Servers as CISA Orders Emergency Patching

Hackers Breach Over 270 Zimbra Servers as CISA Orders Emergency Patching

Hackers have broken into more than 270 email and collaboration servers running Zimbra Collaboration Suite (ZCS) in an active exploitation campaign that pushed the United States Cybersecurity and Infrastructure Security Agency (CISA) to order federal civilian agencies to patch within three days.

The attacks target CVE-2026-73570, a command injection flaw in the SNMP monitoring component that Zimbra ships with its collaboration platform. When SNMP notifications are turned on, the affected code fails to properly sanitize incoming data, and an attacker who sends a specially crafted SMTP request can get the server to run arbitrary operating system commands as the “zimbra” user. No login credentials are needed to pull this off, which is what makes the flaw so dangerous for organizations that run Zimbra as their email backbone.

How the campaign was discovered

Zimbra released a fix for the issue on July 20, 2026, with version 10.1.20 of the platform. For about a month afterward there was no public sign of attackers using it. That changed when CERT Polska, Poland’s national computer emergency response team, identified active exploitation in the wild starting around August 19, 2026. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on August 21 and gave Federal Civilian Executive Branch agencies until August 24 to apply the patch or take the affected systems offline.

Shadowserver, a nonprofit that scans the internet for exposed and compromised systems, has been tracking the fallout. Its scans found more than 12,000 Zimbra instances still reachable from the public internet, with at least 8,200 of those still unpatched as of its most recent count (though Shadowserver notes that not every unpatched server is necessarily exploitable, since some may not have SNMP notifications enabled). Separately, Shadowserver identified more than 270 ZCS instances showing concrete signs of compromise, meaning attackers had already gotten in rather than merely having the opportunity to.

No specific group has claimed responsibility for this particular wave of attacks, and none of the reporting so far names an attacker. It is worth noting, though, that Zimbra has been a repeated target for state-linked hacking groups in the past, including APT28, APT29, and Winter Vivern, which is part of why security researchers are treating this campaign seriously even without firm attribution yet.

What administrators should check

Organizations running Zimbra Collaboration Suite should update to version 10.1.20 or later immediately if they have not already. For servers that may have been exposed before patching, CISA and Shadowserver’s guidance points to reviewing logs for unexpected Zimbra service restarts and checking a handful of specific directories, including /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/, for files created by the zimbra user in the past 30 days that were not part of a normal update or deployment. Disabling SNMP notifications where they are not needed removes the specific trigger for this flaw as an added precaution while patching is completed.

The incident is a reminder that email servers remain high-value targets precisely because of how much sensitive correspondence and how many downstream account credentials pass through them. A single compromised mail server can become a launching point for further intrusion into an organization’s wider network.

Source: BleepingComputer: “Hackers breached over 270 Zimbra servers in ongoing attacks”, with additional details from BleepingComputer’s coverage of the CISA order.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular