Thursday, 1 October 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 1 October 2026 at 06:26

Attackers exploit critical Zimbra vulnerability to steal emails

Microsoft has warned that hackers are actively exploiting a critical flaw in Zimbra Collaboration Suite to obtain email backups and credentials, with more than 270 servers already compromised.

Foto: Ars Technica

Microsoft has warned that attackers are exploiting a critical vulnerability in the Zimbra Collaboration Suite to attempt to steal email backups and authentication credentials from vulnerable organizations.

The flaw, tracked as CVE-2026-73570, allows remote attackers to execute operating system commands without any authentication. Zimbra's maintainer, Synacor, released a patch on July 20 but did not disclose the vulnerability publicly until more than three weeks later.

Hundreds of servers compromised

The security-focused Shadowserver Foundation reported last week that its scans identified 274 compromised instances of Zimbra Collaboration Suite. The total number of servers running the software has fluctuated, from roughly 19,000 in the week following the patch's release down to about 12,000 in subsequent weeks. Shadowserver currently tracks around 10,000 active instances.

How the attacks unfolded

Microsoft said Wednesday that between July 28 and August 7, it detected two distinct scanning tools probing the internet for vulnerable systems. The attackers first tested whether their exploit worked by sending HTTP requests alongside DNS, ICMP, and other out-of-band checks to domains on public services, confirming that command execution succeeded without fully compromising the targeted servers.

Attackers later began using this command-injection capability to deploy malicious payloads. According to Microsoft, this activity included installing JSP web shells and reverse shells, escalating privileges, deploying persistent remote-access tools, and running memory-based code execution. Attackers accessed email systems and harvested authentication and mailbox data, creating archives and transferring them out of the compromised networks.

Microsoft noted that affected organizations span multiple regions and industries, indicating the attacks were not confined to a single sector or geographic area.

CVE-2026-73570 enables unauthenticated remote attackers to run operating system commands through a specially crafted email targeting the ZCS SNMP notification pathway. However, exploitation is only possible when the optional zimbra-snmp package is installed and SNMP notifications are enabled.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category