
Microsoft has disclosed that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite to target organizations and steal email data and authentication credentials.
The vulnerability, designated CVE-2026-73570, enables unauthenticated attackers to execute arbitrary operating system commands through a crafted email message. The flaw specifically targets the SNMP notification processing path within Zimbra and only affects systems with the optional zimbra-snmp package installed and SNMP notifications enabled. Synacor, the Zimbra maintainer, released a patch on July 20 but did not publicly disclose the vulnerability until more than three weeks later. Security researchers at the Shadowserver Foundation subsequently identified approximately 274 compromised instances of the software through network scanning.
Microsoft detected malicious activity spanning from July 28 through August 7, during which time two distinct scanning tools probed internet-connected systems for vulnerable Zimbra servers. The attackers initially validated their exploit functionality by sending HTTP requests and conducting out-of-band checks through public services before proceeding to deploy actual payloads. Once exploitation was confirmed, threat actors installed web shells and reverse shells to maintain persistent access, escalated privileges, and conducted hands-on-keyboard operations on compromised mail infrastructure. Microsoft documented the deployment of memory-backed execution tools and observed the collection of mailbox data, with evidence suggesting attackers created email archives and transferred them off the affected systems.
The attack campaign affected organizations across multiple geographic regions and industry sectors, indicating the exploitation was not limited to any single vertical. Microsoft stated it could not verify whether the attackers successfully exfiltrated collected data. The company provided no attribution regarding the threat actors’ identity or motivations. Administrators managing Zimbra Collaboration Suite installations are advised to upgrade to version 10.1.20 or later and implement additional system hardening measures.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI