
Microsoft has disclosed that a critical vulnerability in the Zimbra Collaboration Suite is being actively exploited by attackers seeking to access email backups and authentication credentials from affected organizations. The flaw, identified as CVE-2026-73570, permits remote execution of operating system commands without requiring any authentication credentials.
Synacor, the maintainer of Zimbra Collaboration Suite, released a patch on July 20, though the vulnerability remained undisclosed for more than three weeks following the fix’s availability. The Shadowserver Foundation reported that its scanning infrastructure detected 274 compromised instances of the software. The total number of active Zimbra servers has declined from approximately 19,000 in the week after the patch was released to around 10,000 as of the latest tracking data.
Starting from July 28 and continuing through August 7, Microsoft identified two distinct scanning tools being used to probe the internet for vulnerable systems. These initial probes employed HTTP requests, DNS queries, ICMP packets, and out-of-band verification checks directed at domains on public services to validate whether the exploit functioned properly. This reconnaissance phase allowed threat actors to confirm successful command execution on vulnerable servers without necessarily compromising them.
Once exploitation proved successful, attackers deployed web shells and reverse shells to establish persistence, escalated privileges, and executed additional malicious payloads in system memory. Investigations by Microsoft revealed that compromised organizations experienced unauthorized access to email systems, with attackers creating archives of messages and transferring data. The observed activity included both automated payload distribution and direct hands-on operations conducted by the threat actors. Microsoft documented affected organizations across multiple geographic regions and industrial sectors, indicating the exploitation was not confined to any particular industry or location.
The vulnerability itself can be leveraged through a specially crafted email targeting the ZCS SNMP notification processing path, though the optional zimbra-snmp package must be installed and SNMP notifications must be enabled for exploitation to succeed. Microsoft recommended that organizations running Zimbra Collaboration Suite upgrade to version 10.1.20 or later and implement additional security hardening measures.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI