Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Solana’s 50,000 SOL security contest did not cover a clock attack disclosed months earlier

    August 20, 2026

    The “Asian water tower” is losing 24 billion tonnes of groundwater every year

    August 20, 2026

    Glass deposit operator appointed after months of wrangling

    August 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Solana’s 50,000 SOL security contest did not cover a clock attack disclosed months earlier
    • The “Asian water tower” is losing 24 billion tonnes of groundwater every year
    • Glass deposit operator appointed after months of wrangling
    • South Koreans make move to cut foreign dependence with domestic ROV capability
    • Trump embraces data centers as backlash shapes races in Wisconsin and nationwide
    • Unite’s mixed message on global heating | Climate crisis
    • Letter in Epstein files details unproven sex trafficking allegations against Trump
    • Cameroon’s 93-year-old President Paul Biya returns after months-long stay abroad
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers Target Zimbra Servers in Active Exploitation Campaign

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 20, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A recently patched Zimbra Collaboration vulnerability is being exploited in the wild, according to Poland’s CERT Polska.

    The security hole is tracked as CVE-2026-73570 and it was patched by the developers of the enterprise email server and collaborative software suite with the release of version 10.1.20, announced on July 20.

    The high-severity flaw exists when the optional ‘zimbra-snmp’ package is installed and SNMP notifications are enabled. 

    An attacker can exploit the vulnerability without authentication to execute arbitrary OS commands as the Zimbra user.

    The Polish CERT announced seeing attacks this week but did not share any details about the active exploitation campaign. It did, however, share some indicators of compromise (IoCs).

    The threat actor behind these attacks and its motivation remain unclear. However, these vulnerabilities can allow threat actors to gain full control of a targeted Zimbra server. The hackers can then establish persistence, access email accounts, harvest credentials, and move laterally to other systems.

    Advertisement. Scroll to continue reading.

    CISA’s KEV catalog currently includes 18 Zimbra Collaboration Suite vulnerabilities, including four added this year. CVE-2026-73570 has yet to be added to the catalog.

    Exploitation of Zimbra vulnerabilities has frequently been linked to Russian and Chinese state-sponsored hackers targeting military and diplomatic intelligence, as well as opportunistic cybercriminals seeking financial gain.

    Related: MLflow Vulnerability Exploited for Cloud Credential Theft

    Related: Critical GitLab Flaw Exploited Shortly After Disclosure

    Related: Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

    active campaign exploitation hackers Servers Target Zimbra
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers poison arrayref Rust crate to push infostealer malware

    Citrix issues critical security updates for its NetScaler devices

    Kriminal breaks out of Grok, Claude guardrails at $12.99

    New Manic Android malware can exfiltrate data through nearby devices

    How MSPs can catch phishing attacks email filters miss

    Critical Elementor Pro bug exposes WordPress sites to RCE attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Solana’s 50,000 SOL security contest did not cover a clock attack disclosed months earlier

    August 20, 2026

    The “Asian water tower” is losing 24 billion tonnes of groundwater every year

    August 20, 2026

    Glass deposit operator appointed after months of wrangling

    August 20, 2026

    South Koreans make move to cut foreign dependence with domestic ROV capability

    August 20, 2026
    Latest Posts

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    July 28, 2026

    OpenAI’s biggest threat may just be open AI

    July 28, 2026

    6 Takeaways From Michigan’s Senate Debate Between Abdul El-Sayed and Haley Stevens

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Solana’s 50,000 SOL security contest did not cover a clock attack disclosed months earlier

    August 20, 2026

    The “Asian water tower” is losing 24 billion tonnes of groundwater every year

    August 20, 2026

    Glass deposit operator appointed after months of wrangling

    August 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.