
A critical vulnerability in Zimbra Collaboration Suite has been the subject of active exploitation by attackers seeking to compromise organizational email systems and steal sensitive data, according to a warning issued by Microsoft.
The flaw, designated CVE-2026-73570, permits threat actors to remotely execute operating system commands without requiring authentication. Synacor, the software maintainer, released a patch on July 20, though the vulnerability remained undisclosed for over three weeks following the patch release. The Shadowserver Foundation reported that security scans identified 274 separate compromised instances of the software. The total number of servers running Zimbra Collaboration Suite has declined from approximately 19,000 in the week after the patch was released to around 10,000 currently being tracked.
Between July 28 and August 7, Microsoft detected two distinct scanning tools being used to probe for vulnerable systems connected to the internet. The attackers employed a validation method involving HTTP requests and DNS and ICMP checks directed at public services to confirm successful exploitation without immediately compromising systems. Once attackers gained confidence in their exploit effectiveness, they progressed to deploying malicious software and conducting unauthorized access operations.
Following successful exploitation, attackers installed web shells and reverse shells to maintain access, escalated privileges, and deployed persistent remote-access tools. Investigators observed attackers accessing email systems, collecting authentication information and mailbox contents, creating archives, and transferring data. Microsoft noted the activity involved both automated methods and direct operator involvement on compromised mail servers, affecting organizations across multiple regions and industries.
The vulnerability functions through a specially crafted email message targeting the ZCS SNMP notification system when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Insufficient sanitization of input data allows embedded shell commands to execute using the privileges of the zimbra service account. Microsoft advised administrators to update to version 10.1.20 or later and implement additional system hardening measures.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI