Attackers have been exploiting critical Zimbra flaw to steal emails
Attackers are exploiting critical Zimbra flaw CVE-2026-73570 to steal organizational email and credentials.
Microsoft warned that attackers exploited CVE-2026-73570, a critical unauthenticated command-injection flaw in Zimbra Collaboration Suite, to steal email and credentials. Synacor patched it on July 20 but did not disclose the bug for more than three weeks. From July 28 to August 7, Microsoft saw scanning followed by JSP web shells, reverse shells, privilege escalation, and hands-on-keyboard access across multiple regions and industries. Shadowserver reported 274 compromised instances and currently tracks about 10,000 Zimbra servers. The flaw works only when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
- CVE-2026-73570 allows unauthenticated OS commands via Zimbra's SNMP notification path.
- Synacor patched on July 20 but delayed disclosure for over three weeks.
- Microsoft observed web shells, reverse shells, credential theft, and email archiving.
- Shadowserver found 274 compromised instances among about 10,000 tracked servers.
- Exploitation requires the optional zimbra-snmp package and SNMP notifications enabled.
Vulnerabilities mentionedAll →
- CVE-2026-735708.972%Unauthenticated OS Command Injection RCE in Synacor Zimbra Collaboration Suitepublished · Synacor Zimbra Collaboration Suite (ZCS) KEV PoC ×5
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article323 words · extracted from arstechnica.com · click to collapse
Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned.
The vulnerability, tracked as CVE-2026-73570, lets attackers remotely issue operating system commands without authentication. Zimbra maintainer Synacor issued a patch on July 20, but didn’t disclose the vulnerability for more than three weeks after that. The security-focused Shadowserver Foundation said last week that its scans found that 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks following that. Currently, Shadowserver is tracking about 10,000 instances.
Look, ma, no authorization
From July 28 to August 7, Microsoft said Wednesday, the company detected two distinct scanning tools probing the Internet for vulnerable endpoints. The attackers first validated their exploit worked by sending HTTP, requests and DNS, ICMP, and out-of-band identity checks to domains hosted on public services. The probes allowed the attackers to confirm the exploit successfully executed commands on vulnerable servers without actually compromising them. Eventually, the attackers began using their command injection capability to install malicious payloads. Microsoft wrote:
Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution. Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed. The activity included both automated payload delivery and hands-on-keyboard operations on compromised mail servers. Microsoft observed affected organizations in more than one region and industry. Based on the environments investigated, exploitation was not limited to a single sector or geographic area.
CVE-2026-73570 allows remote attackers with no credentials to run operating system commands through a crafted email that targets the ZCS SNMP notification path but only when an optional zimbra-snmp package is in place and SNMP notifications are enabled.