Zimbra flaw exploited to steal emails and credentials

arstechnica.com —

Microsoft warned that hackers are exploiting a critical Zimbra Collaboration Suite vulnerability, CVE-2026-73570, to steal emails and authentication credentials from vulnerable organizations. The flaw allows remote OS command injection without authentication. Synacor patched the flaw on July 20 but delayed disclosure for over three weeks. Shadowserver Foundation found 274 compromised instances, with vulnerable servers dropping from 19,000 to about 10,000 currently. Microsoft detected two scanning tools probing for vulnerable endpoints from July 28 to August 7. Attackers deployed JSP web shells, reverse shells, and remote-access tools, accessing email and collecting mailbox data. Exploitation required the optional zimbra-snmp package with SNMP notifications enabled. Microsoft urged administrators to update to version 10.1.20 or later, but provided no details on attacker identity or data exfiltration confirmation.


With a significance score of 2.8, this news ranks in the top 16% of today's 33312 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Zimbra flaw exploited to steal emails and credentials | News Minimalist