Hackers Target 270 Zimbra Servers in Ongoing Cyberattacks

www.news4hackers.com-hackers-target-270-zimbra-servers-in-ongoing-cyberattacks-hackers-target-270-zimbra-servers-in-ongoing-cyberattacks

Over 270 Zimbra servers have been compromised through remote code execution campaigns exploiting a critical vulnerability in the Zimbra Collaboration Suite, according to recent cybersecurity reports.

Overview of the Zimbra Vulnerability

Cybercriminals have exploited a severe flaw in the Zimbra Collaboration Suite (ZCS), enabling unauthenticated remote code execution via a command injection vulnerability in the SNMP monitoring component. The flaw, designated CVE-2026-73570, was addressed by Synacor in ZCS version 10.1.20 released on July 20. Threat actors have leveraged this vulnerability to infiltrate servers, with Polish cybersecurity authority CERT Polska reporting active exploitation in the wild.

Details of the Vulnerability

The vulnerability allows attackers to execute arbitrary code remotely when SNMP notifications are enabled. Indicators of compromise include unexpected Zimbra service restarts and the creation of files in directories such as /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ by the zimbra user within the past 30 days. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring U.S. federal agencies to apply patches by August 24.

Response and Mitigation Efforts

Shadowserver, a threat intelligence organization, reported 274 compromised Zimbra instances as of August 22, with at least 8,200 unpatched systems identified. While not all unpatched systems may be exploitable due to the vulnerability’s non-default configuration, the incident underscores the urgency of patch management. Organizations are advised to monitor logs for anomalies and apply updates promptly.

Historical Context of Zimbra Exploits

Zimbra vulnerabilities have repeatedly been targeted by advanced persistent threat (APT) groups. In March, researchers linked APT28 (Russian military intelligence) to attacks on Ukrainian government servers using a stored cross-site scripting (XSS) flaw. Earlier in 2024, APT29 (Midnight Blizzard) exploited a prior ZCS vulnerability to steal credentials, while Russian cyber espionage actors known as Winter Vivern accessed NATO-aligned accounts via Zimbra webmail portals.

Security Assessment Findings

A 2026 report analyzing 338 million simulations revealed that 37% of attacker actions were blocked when valid credentials were compromised. This highlights gaps in defense mechanisms, even with patching efforts. The ongoing exploitation of Zimbra emphasizes the risks of legacy systems and the need for proactive security measures.

Recommendations for Organizations

Organizations must prioritize patch management, monitor for suspicious activity, and implement multi-layered defenses. Proactive strategies, including regular audits and employee training, are critical to mitigating exposure to similar threats. The Zimbra incidents serve as a stark reminder of the evolving cybersecurity landscape.

According to a 2026 report, 37% of attacker actions were blocked when valid credentials were compromised, underscoring the need for robust mitigation strategies despite patching efforts.


Blog Image

About Author

en_USEnglish