# More than 270 Zimbra servers breached in attacks on patched flaw

_Tuesday, August 25, 2026 at 8:04 AM EDT · Security · Latest · Tier 1 — Major_

![More than 270 Zimbra servers breached in attacks on patched flaw — Primary](https://www.bleepstatic.com/content/hl-images/2026/08/25/Zimbra.jpg)

Threat actors have compromised more than 270 Zimbra instances in remote-code-execution attacks exploiting CVE-2026-73570, according to Shadowserver scans cited by BleepingComputer. Synacor patched the unauthenticated command-injection flaw in Zimbra Collaboration Suite version 10.1.20 on July 20. Shadowserver reported 274 compromised instances in scans on August 22 and at least 8,200 unpatched instances, though the vulnerable configuration is not enabled by default.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/)

---
Canonical: https://techandbusiness.org/newswire/A1ZL-JeSZ3cd3S0WErLdXD
Retrieved: 2026-08-25T14:33:11.175Z
Publisher: Tech & Business (techandbusiness.org)
