Mastodon Skip to content
pulseofnations. Real News. Global Impact.
Subscribe
live markets
S&P 5007,677.28▲ 3.58%NASDAQ26,151.30▲ 4.71%DOW53,577.40▲ 3.14%GOLD4,699.60▲ 15.34%WTI80.33▼ 2.76%BRENT85.25▼ 3.52%EUR/USD1.1667▲ 2.55%USD/JPY159.01▼ 2.94%DXY98.98▼ 2.50%BTC$79,015▼ 1.73%ETH$2,466▼ 1.27%SOL$96.94▼ 4.34%TOTAL CRYPTO$2.68T▼ 4.10%

274 Zimbra Servers Hacked as CISA Patch Deadline Expires

At least 274 internet-facing Zimbra instances confirmed compromised via CVE-2026-73570 as CISA three-day remediation deadline for federal agencies expires.

Partner Surfshark VPN

At least 274 internet-facing Zimbra Collaboration Suite servers have been compromised through active exploitation of CVE-2026-73570, a critical command-injection vulnerability, as the US Cybersecurity and Infrastructure Security Agency three-day patching deadline for federal civilian agencies expired on Monday.

The Shadowserver Foundation confirmed the breach tally on Monday, reporting that dozens of additional Zimbra instances worldwide were also compromised. Nearly 700 US-based organizations remain on vulnerable versions of the software, leaving them open to ongoing attacks through the SNMP notification flaw.

How the Attack Works

CVE-2026-73570 affects Zimbra installations with the zimbra-snmp package installed and SNMP notifications enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that result in arbitrary shell command execution as the Zimbra user.

Successful exploitation grants attackers broad access to the targets mail platform without requiring valid credentials. From there, operators can deploy web shells, steal email data, modify server configurations, establish persistence, or use the compromised server to pivot into other systems within an organization.

Zimbra developer Synacor disclosed the flaw on June 26 but did not release a patched version until July 20, in ZCS v10.1.20. CERT Polska first flagged active exploitation on August 14, prompting CISA to add the CVE to its Known Exploited Vulnerabilities catalog on August 21 with a three-day remediation mandate for federal agencies.

A Recurring Zimbra Problem

The vulnerability has been exploited by both state-sponsored actors and opportunistic cybercriminals. In July, CISA and the National Security Agency warned that Russia-linked hackers were targeting Ukrainian and Western governments using a separate Zimbra flaw. Previous Zimbra-based campaigns have hit the Brazilian military and organizations across the healthcare and energy sectors.

Security teams should inspect Zimbra logs for suspicious service-status changes indicating an unknown payload toggling between stopped and running states. CERT Polska also recommends checking for recently created files owned by the zimbra user in the webapps directories and under /tmp.

Administrators who cannot patch immediately should verify whether the SNMP trap functionality is necessary and disable it if not required. The approximately 8,200 instances still running older versions are not all necessarily vulnerable, since exploitation requires SNMP notifications to be enabled, a non-default configuration.

With hundreds of servers confirmed breached and thousands more running unpatched software, the Zimbra flaw represents one of the most actively exploited vulnerabilities of August 2026. Organizations worldwide are urged to upgrade to version 10.1.20 or later immediately.

SourcesHelp Net Security; Cybersecurity Dive; CERT Polska; Shadowserver Foundation; CyberSecurityNews
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch Eight AI Agents Breach Asian Gov, Steal 2,500 Records Read →