Microsoft catches hackers exploiting Zimbra bug before disclosure

theregister.com —

Microsoft has detected active exploitation of a critical Zimbra mail server vulnerability, CVE-2026-73570, before its public disclosure, with attackers probing the flaw weeks in advance and escalating to credential theft and system compromise. The unauthenticated command injection flaw, affecting Zimbra Collaboration Suite with optional SNMP monitoring enabled, was patched in version 10.1.20 on July 20 but only publicly disclosed on August 13. Microsoft observed two scanning tools probing the vulnerable component between July 28 and August 7, with attackers deploying web shells, reverse shells, and privilege escalation techniques, including gaining root access on one system. Attackers targeted Zimbra credentials and mailbox data, using tools like AzCopy to exfiltrate backups to Azure Blob Storage, and exploited SSH relationships to move between servers. Microsoft advises updating to version 10.1.20 or later, or removing the SNMP package to mitigate risk, though the threat actor remains unidentified.


With a significance score of 3.3, this news ranks in the top 12% of today's 33330 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Microsoft catches hackers exploiting Zimbra bug before disclosure | News Minimalist