Attackers exploit Zimbra RCE flaw, compromise 274 servers worldwide
Shadowserver identified 274 Zimbra Collaboration Suite instances already breached through exploitation of CVE-2026-73570, a command injection flaw in the SNMP monitoring component that allows unauthenticated remote code execution. Synacor patched the bug in ZCS 10.1.20 on July 20, but Shadowserver still counts over 8,200 unpatched instances exposed online, though not all are necessarily exploitable due to non-default configuration requirements.