Attackers have already compromised hundreds of Zimbra Collaboration Suite servers through a high-severity remote code execution vulnerability, according to BleepingComputer. The report says the attacks target CVE-2026-73570, a flaw in Zimbra’s SNMP monitoring component that can allow unauthenticated code execution when SNMP notifications are enabled. The most concrete compromise count comes from Shadowserver, the internet-exposure and threat-monitoring group cited by BleepingComputer. Shadowserver reported 274 compromised Zimbra instances in scans for exploitation artifacts on August 22. It also said it saw at least 8,200 unpatched instances, while cautioning that unpatched systems are not automatically exploitable because the vulnerable condition depends on a non-default configuration. Synacor patched the vulnerability in Zimbra Collaboration Suite version 10.1.20 on July 20, BleepingComputer reports. That means the current incident is not centered on an unknown zero-day, based on the provided reporting, but on exploitation of a known and patched vulnerability across exposed systems that have not yet been remediated or may already have been accessed. CERT Polska first flagged active exploitation last Monday, according to the report. The Polish Computer Emergency Response Team advised security teams to review logs for signs such as unexpected Zimbra service restarts and to look for files created by the zimbra user during the past 30 days in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/. The U.S. Cybersecurity and Infrastructure Security Agency also added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog after CERT Polska’s warning, BleepingComputer says. CISA ordered U.S. Federal Civilian Executive Branch agencies to patch affected systems within three days, by August 24. The risk profile is meaningful because Zimbra is an email and collaboration platform used by large numbers of organizations, including businesses and government agencies, according to BleepingComputer. Email servers are high-value targets: successful access can expose messages, credentials, attachments, and internal communication flows. The report also places this incident in a longer pattern of Zimbra exploitation. BleepingComputer notes that Zimbra vulnerabilities have repeatedly been targeted by cybercriminal and state-sponsored groups, including prior activity involving APT28, APT29, and Winter Vivern against Zimbra webmail or email environments. Those past cases do not prove attribution in the current campaign, but they help explain why defenders treat exposed Zimbra flaws as urgent. Who benefits: Attackers benefit from organizations that leave externally reachable Zimbra systems unpatched or fail to check for prior compromise. Defenders benefit from the public indicators and the narrow configuration caveat around SNMP notifications. Who's exposed: Organizations running Zimbra Collaboration Suite, especially internet-exposed instances with SNMP notifications enabled, are the clearest exposure group described in the reporting. U.S. federal civilian agencies were explicitly required by CISA to patch by August 24.