Attackers have been exploiting critical Zimbra flaw to steal emails
What happened
Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned . Zimbra maintainer Synacor issued a patch on July 20, but didn’t disclose the vulnerability for more than three weeks after that.
The security-focused Shadowserver Foundation said last week that its scans found that 274 separate instances of the Zimbra Collaboration Suite had been compromised. A simple email gives the attackers the ability to remotely inject OS commands.
The vulnerability, tracked as CVE-2026-73570 (the public catalogue number for a specific software flaw), lets attackers remotely issue operating system commands without authentication. Currently, Shadowserver is tracking about 10,000 instances.
Key facts
- The security-focused Shadowserver Foundation said last week that its scans — found: that 274 separate instances of the Zimbra Collaboration Suite had been compromised
Sources & evidence
- Ars Technica Reporting source
Attackers have been exploiting critical Zimbra flaw to steal emails ↗
https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/