As cited
Copy frozen at (site build).
vulnerabilities
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
The Shadowserver Foundation reported that at least 274 internet-facing Zimbra Collaboration Suite instances have been compromised through exploitation of CVE-2026-73570, a code injection vulnerability. Synacor released a patch for this flaw in Zimbra Collaboration Suite version 10.1.20 on July 20, 2026.
Why it matters: Organizations running unpatched Zimbra Collaboration Suite versions are exposed to active code injection attacks and should apply the vendor patch immediately.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
The Shadowserver Foundation reported that at least 274 internet-facing Zimbra Collaboration Suite instances have been compromised through exploitation of CVE-2026-73570, a code injection vulnerability. Synacor released a patch for this flaw in Zimbra Collaboration Suite version 10.1.20 on July 20, 2026.
Why it matters: Organizations running unpatched Zimbra Collaboration Suite versions are exposed to active code injection attacks and should apply the vendor patch immediately.
- Source published
- First seen by Cybersecurity Tracker