"Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22," Shadowserver warned.
CVE-2026-73570 and the SNMP command-injection flaw in ZCS
The vulnerability at the center of the current wave is tracked as CVE-2026-73570. According to published advisories, the flaw allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled. Synacor issued a fix for the defect in the form of ZCS version 10.1.20, released on July 20.
Scope of compromise: Shadowserver's scans and exposed instances
Shadowserver, a threat-security watchdog, reported that its scans detected artifacts of exploitation on 274 Zimbra instances as of August 22, 2026. In the same update the organization noted at least 8,200 instances remain unpatched for CVE-2026-73570, while cautioning that this count "does not mean exploitable as the vuln is in a non default config." The snapshot from Shadowserver frames the incident as an active and spreading campaign targeting Internet-exposed Zimbra servers.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSynacor patch, CERT Polska indicators, and CISA action
Synacor released ZCS 10.1.20 on July 20 to patch the SNMP-related command-injection bug. CERT Polska — the Polish Computer Emergency Response Team — flagged the vulnerability as being targeted in the wild and advised security teams to check their logs for specific signs of intrusion. CERT Polska called out unexpected Zimbra service restarts and instructed defenders to search for files created in these paths by the zimbra user over the last 30 days: /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
Following CERT Polska's warning, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days — a deadline set for August 24.
Prior Zimbra-related intrusions cited in public reporting
Public reports cited in the advisory note that Zimbra vulnerabilities have been frequent targets for both cybercriminals and state-sponsored groups. In March, Seqrite Labs researchers reported that APT28 exploited a stored cross-site scripting (XSS) Zimbra vulnerability to breach Ukrainian government servers. U.S. and UK cyber agencies in October 2024 warned that actors linked to the Russian Foreign Intelligence Service — tracked as APT29, Midnight Blizzard, and Cozy Bear — had previously compromised Zimbra servers using a ZCS flaw to steal email account credentials.
What this means for technologists, U.S. federal agencies, and affected organizations
- Technologists and security teams: CERT Polska's guidance points to concrete forensic checks — look for unexpected Zimbra service restarts and files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ within the prior 30 days. Installing ZCS 10.1.20 is the patch Synacor released to remediate CVE-2026-73570.
- U.S. Federal Civilian Executive Branch (FCEB) agencies: CISA added the flaw to its KEV catalog and set a three-day remediation mandate, with a patching deadline of August 24 — a formal, time-bound requirement for federal systems.
- Affected enterprises and government agencies using Zimbra: Shadowserver's scans indicate active compromises (274 instances) alongside a substantial number of unpatched servers (at least 8,200 instances). Organizations running Internet-exposed Zimbra instances should assess whether SNMP notifications are enabled and verify whether the July 20 update to ZCS 10.1.20 has been applied.
The record assembled by Synacor, CERT Polska, CISA, and Shadowserver presents a compact but urgent chain: a high-severity SNMP command-injection bug, a vendor patch on July 20, public detection of active targeting, an uptick of confirmed compromises on August 22, and a constrained federal remediation deadline. The quantified findings — 274 compromised instances and at least 8,200 unpatched instances — frame this as a fast-moving exploitation window against a widely deployed collaboration platform used by "hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide."
How many of the unpatched instances will show evidence of exploitation, how quickly organizations will apply the ZCS 10.1.20 update, and whether forensic checks turn up additional signs of persistence on breached systems are the immediate, concrete questions left by the available facts.
Source: BleepingComputer — "Hackers breached over 270 Zimbra servers in ongoing attacks"




