Hackers exploiting critical Zimbra flaw to steal emails, Microsoft warns

Unpatched command injection bug CVE-2026-73570 under active attack

By LineZotpaper
Published
Read Time2 min
Attackers have been actively exploiting a critical unauthenticated command injection vulnerability in the Zimbra Collaboration Suite to steal email backups and authentication credentials from vulnerable organizations, Microsoft warned on Wednesday. The flaw, tracked as CVE-2026-73570, was patched by Zimbra maintainer Synacor on July 20, but was not publicly disclosed until more than three weeks later, leaving a window for exploitation.

Microsoft said it detected two distinct scanning tools probing the internet for vulnerable Zimbra endpoints between July 28 and August 7. The attackers first validated their exploits by sending HTTP requests, DNS, ICMP and out-of-band identity checks to domains hosted on public services, confirming they could execute commands on vulnerable servers without actually compromising them. They then used the command injection capability to install malicious payloads.

The vulnerability allows remote attackers to issue operating system commands without authentication. Microsoft's warning follows a report from the Shadowserver Foundation, which said last week that its scans found 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated since the patch was released, from about 19,000 instances in the week after the patch to roughly 12,000 in subsequent weeks. Shadowserver is currently tracking about 10,000 instances.

Organizations running Zimbra Collaboration Suite are urged to apply the patch immediately and check for signs of compromise, particularly on internet-facing mail servers.

§

Analysis

Why This Matters

  • Zimbra Collaboration Suite is widely used by organizations for email and collaboration, and internet-facing mail servers are high-value targets.
  • Active exploitation can expose email backups and authentication credentials, potentially compromising sensitive communications and enabling further attacks.
  • The delayed disclosure after patching may have left many organizations unaware of the risk and exposed to attackers.

Background

Zimbra Collaboration Suite is a common email and collaboration platform used by enterprises, universities and government agencies. Because mail servers are often exposed to the internet, vulnerabilities in software like this have historically been attractive to attackers seeking access to internal communications and credentials. The current incident highlights the risk of exploitation during the gap between a patch being issued and the vulnerability being publicly disclosed.

Key Perspectives

Microsoft: The company detected active scanning and exploitation attempts, and warns that attackers have used the flaw to install malicious payloads and steal data. Synacor, Zimbra's maintainer: The company issued a patch on July 20, but did not disclose the vulnerability for more than three weeks, a delay that may have contributed to continued exposure. Shadowserver Foundation: The security monitoring group has identified hundreds of compromised instances and tracks thousands of remaining Zimbra servers, suggesting many systems may still be vulnerable. Organizations running Zimbra: They face the immediate challenge of determining whether their email systems were targeted and whether email backups or credentials were stolen.

What to Watch

  • The number of Zimbra Collaboration Suite instances tracked by Shadowserver, to see whether patch adoption improves or exposed systems remain.
  • Reports of additional compromises or payload installations tied to CVE-2026-73570.
  • Whether further technical details or indicators of compromise are released to help organizations detect and respond to the attacks.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.