Skip to content
feed: live
>_0dayNews
zimbra
● Breaking

270 Zimbra Servers Breached as KEV Deadline Expires

Attackers have compromised 270+ Zimbra ZCS servers via CVE-2026-73570 SNMP RCE. CISA's Aug 24 KEV patch deadline is past; upgrade to ZCS 10.1.20 now.

270 Zimbra Servers Breached as KEV Deadline Expires
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·1 min read

Attackers have compromised more than 270 Zimbra Collaboration Suite servers in remote code execution attacks against CVE-2026-73570, per BleepingComputer’s reporting. The breach count puts a concrete number on what began as a confirmed-exploitation disclosure on August 20 — and it arrived the day after CISA’s remediation deadline for federal agencies expired.

The vulnerability

CVE-2026-73570 is an unauthenticated command injection in Zimbra Collaboration Suite’s SNMP handler. A remote attacker with access to SNMP ports (161/UDP, 162/UDP) can send a crafted request to execute arbitrary commands on the ZCS host — no credentials required. The flaw carries a CVSS score of 8.9 (High) and affects all ZCS installations below version 10.1.20.

The fix shipped with Zimbra 10.1.20 in July 2026. The servers now confirmed compromised are the ones that haven’t applied it.

CISA timeline

CISA added CVE-2026-73570 to the Known Exploited Vulnerabilities catalog on August 21 and set August 24 as the remediation due date for federal civilian executive branch agencies — a three-day window. That deadline has passed.

Dark Reading notes that the case illustrates the shrinking gap between patch release and mass exploitation: the fix was available since July, exploitation was confirmed active on August 20, and within five days there are over 270 confirmed compromises.

What to do

Patch: Upgrade to Zimbra ZCS 10.1.20 or later. The fix has been available since July. There is no good reason to defer at this point.

Network mitigate while patching: Block inbound traffic to SNMP ports 161/UDP and 162/UDP from untrusted network segments at the perimeter. This limits exposure but does not replace patching.

Assume breach if unpatched and exposed: Any ZCS instance running below 10.1.20 with SNMP reachable from an untrusted segment since August 20 should be treated as compromised pending forensic review. Check ZCS host logs for anomalous process execution originating from the SNMP service.

Attribution for the active campaign is unconfirmed in current public reporting.

For the initial technical breakdown and CERT Polska’s indicators of compromise, see our August 21 coverage. For context on prior Zimbra targeting, see the Void Blizzard email-theft campaign from July and the 10.1.20 patch release notes analysis.

Related CVEs
  • [ HIGH ]CVE-2026-73570Zimbra ZCS SNMP Command Injection — Unauthenticated RCE

Found this useful? Share it.