Attackers have been exploiting critical Zimbra flaw to steal emails

by | Oct 7, 2026 | Technology

Attackers have been exploiting critical Zimbra flaw to steal emails

Microsoft has disclosed that threat actors have been actively exploiting a critical vulnerability in the Zimbra Collaboration Suite to compromise organizations globally. The flaw, designated CVE-2026-73570, permits unauthenticated remote attackers to execute operating system commands through a specially crafted SMTP request that targets the ZCS SNMP notification path, provided the optional zimbra-snmp package is installed and SNMP notifications are enabled.

Synacor, the maintainer of Zimbra Collaboration Suite, released a patch on July 20, but did not publicly disclose details about the vulnerability for more than three weeks afterward. The Shadowserver Foundation subsequently conducted scans that identified 274 compromised instances of the software. The number of exposed servers has declined over time, from 19,000 in the week following the patch release to approximately 10,000 currently.

Microsoft detected two separate scanning tools probing for vulnerable systems between July 28 and August 7. Initial reconnaissance involved HTTP requests and DNS and ICMP probes to validate successful exploitation without directly compromising servers. Following these validation activities, attackers deployed malicious web shells and reverse shells, escalated privileges, and installed persistent remote-access tools. Investigators observed both automated payload delivery and direct hands-on-keyboard activity on compromised mail servers across multiple regions and industries.

Once systems were compromised, attackers accessed email systems and harvested authentication data and mailbox contents, creating archives for subsequent transfer. Microsoft stated it could not confirm whether the exfiltrated data was successfully removed from the affected networks. The company provided no attribution regarding the attackers’ identities or whether they represented nation-state actors or criminal groups.

Administrators managing Zimbra Collaboration Suite installations are advised to upgrade to version 10.1.20 or later and implement additional system hardening measures recommended by the vendor.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI