Sunday, August 30, 2026
LIVEGiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
NetworkAI-assisted

Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation

CVE-2026-73570 lets an unauthenticated attacker run system commands through Zimbra's SNMP notification handling. Shadowserver counts hundreds of breached instances, with over 8,000 still unpatched.

Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation

Twenty days. That is roughly how long it took between the disclosure of CVE-2026-73570 and Shadowserver's count of 274 compromised Zimbra Collaboration Suite instances worldwide. The flaw, rated 8.9 on the CVSS scale, sits in how Zimbra processes SNMP notifications, and it lets an attacker with no credentials at all execute operating system commands as the zimbra user.

This is not a theoretical bug confined to a research writeup. The United States leads the compromised count with 46 instances, followed by Sweden with 21, France with 20 and Germany with 17. That spread says something specific: a lot of small and mid-sized organizations still run their own Zimbra mail server directly exposed to the internet, with no reverse proxy or web application firewall sitting in front of it.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 21, which triggers a mandatory patching deadline for US federal agencies. Everyone else gets the same advice without the legal obligation: upgrade to Zimbra Collaboration Suite 10.1.20 or later, now.

The United States leads the compromised count with 46 instances, followed by Sweden with 21, France with 20 and Germany with 17.
Leo Underwood · The Hacking Post

Patching alone may not be enough. Several researchers tracking the exploitation wave point out that updating a server after it has already been compromised does not remove whatever the attacker planted there, a backdoor account, a scheduled task, a webshell tucked into an upload directory. For any Zimbra deployment that was internet-facing before the patch landed, log review is the minimum, and a clean reinstall is the safer call if there is any doubt.

More than 8,200 instances remain unpatched according to the latest scans, a number that all but guarantees this list of compromised servers keeps growing through September. Mail servers make an unusually attractive target too: once inside, an attacker sits on every password reset link, every internal thread, every attachment that ever passed through the box.

Advertisement

SNMP notification handling being reachable without authentication is itself the part worth dwelling on. That subsystem exists to feed monitoring tools, not to process input from the open internet, and a pre-auth path into it suggests the kind of interface that rarely gets the same scrutiny as a login form. Zimbra has spent years positioning itself as the budget-friendly alternative to Exchange for ISPs, universities and government bodies that do not want a Microsoft licensing bill, which is exactly the demographic least likely to run a dedicated security team watching CISA's KEV catalog in real time.

Based on reporting by Help Net Security.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories