zimbra News Articles
Recent news articles refferecing the vendors vulnerabilities.
Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570
4 days ago
Exploited RCE Flaws and Infrastructure Attacks Define this Cybersecurity Week in August 2026 | eSecurity Planet
Weekly summary of Cybersecurity Insider newsletters for August 2026.
6 days ago
274 Zimbra Servers Compromised, 8,200 Unpatched
Attackers exploited CVE-2026-73570 to compromise 274 Zimbra servers, while 8,200 systems remain unpatched. Learn what administrators should check.
1 week ago
Hackers have breached hundreds of Zimbra servers, despite a patch having been available for weeks
The flaw allows attackers to trigger cross-site scripting, sensitive information disclosure, security restriction bypass, and remote code execution
1 week ago
Zimbra SNMP flaw actively exploited, 274 servers hit
CVE-2026-73570 is under active exploitation, and 274 Zimbra mail servers are already compromised. Here is what changed, and what admins should check now.
1 week ago
Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
1 week ago
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks - Help Net Security
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570.
1 week ago
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
CISA issued a 3-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
1 week ago
Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild - IT Security News
2026-08-24 21:08 CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows...
1 week ago
Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild
Threat Actors Exploit Critical Zimbra OS Command Injection Flaw (CVE-2026-73570) for Remote Code Execution.
1 week ago

CISA orders urgent patching of actively exploited Zimbra flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days.
1 week ago
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution - SwapUpdate
Ravie LakshmananAug 20, 2026Vulnerability / Email Security
2 weeks ago
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Attackers exploit CVE-2026-73570 on Zimbra servers with zimbra-snmp installed and SNMP notifications enabled, allowing unauthenticated RCE.
2 weeks ago
Critical Zimbra RCE flaw now actively exploited in attacks
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS).
2 weeks ago
Hackers Target Zimbra Servers in Active Exploitation Campaign
CVE-2026-73570, a recently patched Zimbra Collaboration vulnerability that allows remote command execution, is being exploited in the wild.
2 weeks ago
Russian Hackers Exploit Zimbra 0-Day Against US, Ukraine Targets
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian spies exploited CVE-2025-66376 in Zimbra to steal 90 days of mail, passwords, 2FA codes, and directories from Western targets.
Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
Over 10,000 Zimbra Collaboration Suite (ZCS) instances exposed online are vulnerable to ongoing attacks exploiting a cross-site scripting (XSS) security flaw.
Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
Hackers part of APT28, a state-backed threat group linked to Russia's military intelligence service (GRU), are exploiting a Zimbra Collaboration Suite (ZCS) vulnerability in attacks targeting Ukrainian government entities.
Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
Hackers part of APT28, a state-backed threat group linked to Russia's military intelligence service (GRU), are exploiting a Zimbra Collaboration Suite (ZCS) vulnerability in attacks targeting Ukrainian government entities.
Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376
Russian APT exploits a critical XSS flaw in Zimbra, tracked as CVE-2025-66376, running scripts via HTML emails to target users in Ukraine.
CISA Adds Exploited Zimbra Collaboration Suite Flaw to Warning List
CISA has officially added a critical vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its KVE catalog.
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks
Interlock exploits CVE-2026-20131 zero-day since Jan 26, enabling root access on Cisco FMC, increasing ransomware risks.
U.S. CISA adds Microsoft SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalog.