Hackers breached over 270 Zimbra servers in ongoing attacks
Hackers have compromised over 270 Zimbra servers in ongoing attacks exploiting a high-severity vulnerability in the Zimbra Collaboration Suite. The vulnerability, tracked as CVE-2026-73570, allows unauthenticated attackers to gain code execution remotely.
Intelligence analysis by Llama

Threat actors have exploited a Zimbra Collaboration Suite vulnerability to breach over 270 servers, with the Polish Computer Emergency Response Team (CERT Polska) warning security teams to check their logs for suspicious activity.
Imagine you have a special kind of computer program that helps you communicate with others. This program is called Zimbra, and it's like a big email server that lots of people use. Unfortunately, some bad people found a way to break into this program and steal important information. This is like someone breaking into your house and taking your valuables. It's not good, and we need to make sure we fix the problem so it doesn't happen again.
Analysis
Zimbra Vulnerability Overview
The recent breach of over 270 Zimbra servers has highlighted the importance of patching vulnerabilities in collaboration software. The vulnerability, tracked as CVE-2026-73570, allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
Impact of the Breach
The breach of Zimbra servers has significant implications for organizations that use the Zimbra Collaboration Suite. Hackers can exploit the vulnerability to gain access to sensitive data, including emails containing confidential information. The breach also highlights the importance of regular security updates and patches to prevent such attacks.
Response to the Breach
The Polish Computer Emergency Response Team (CERT Polska) has warned security teams to check their logs for suspicious activity, including the Zimbra service restarting unexpectedly, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days. The Cybersecurity and Infrastructure Security Agency (CISA) has also added the flaw to its KEV catalog and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.
Key points
- Over 270 Zimbra servers have been compromised in ongoing attacks exploiting a high-severity vulnerability.
- The vulnerability, tracked as CVE-2026-73570, allows unauthenticated attackers to gain code execution remotely.
- The Polish Computer Emergency Response Team (CERT Polska) has warned security teams to check their logs for suspicious activity.
- The Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its KEV catalog and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days.
If the vulnerability is patched quickly, the number of compromised Zimbra servers will decrease, and the risk of further breaches will be reduced. Additionally, the awareness raised by this incident may lead to improved security measures being implemented by organizations that use the Zimbra Collaboration Suite.
If the vulnerability is not patched quickly, the number of compromised Zimbra servers will continue to rise, and the risk of further breaches will increase. This could lead to a significant loss of sensitive data and potentially even more severe consequences.



