By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Exploit Critical Zimbra Flaw for Email Theft

Hackers have been actively exploiting a critical vulnerability within the Zimbra Collaboration Suite, a widely used email and collaboration platform, with the primary objective of stealing email backups and authentication credentials from vulnerable organizations. Microsoft has issued a warning regarding this ongoing exploitation. The vulnerability, officially designated as CVE-2026-73570, permits attackers to remotely issue operating system commands on affected servers without requiring any form of authentication. This allows for significant unauthorized access and control over the compromised systems.
Zimbra's maintainer, Synacor, released a patch to address this critical flaw on July 20. However, the company delayed disclosing the vulnerability publicly for over three weeks following the patch's release. This delay may have provided attackers with an extended window of opportunity to identify and exploit vulnerable systems. The security-focused Shadowserver Foundation reported last week that its scans had identified 274 distinct instances of the Zimbra Collaboration Suite that had already been compromised by these attacks. The number of servers running the Zimbra software has seen fluctuations, decreasing from approximately 19,000 servers in the week immediately after the patch was issued to around 12,000 in the subsequent weeks. Currently, Shadowserver is actively tracking about 10,000 instances of the software.
Microsoft detailed that between July 28 and August 7, the company detected two separate scanning tools actively probing the internet for endpoints vulnerable to CVE-2026-73570. The initial phase of the attack involved attackers validating their exploit's effectiveness. They achieved this by sending various types of network requests, including HTTP requests and DNS, ICMP, and out-of-band identity checks, to domains hosted on public services. These probes allowed the attackers to confirm that their command injection exploit was successfully executing commands on the vulnerable servers without necessarily causing a full compromise at that stage. Following successful validation, the attackers transitioned to leveraging their command injection capabilities to deploy malicious payloads onto the compromised systems, thereby escalating their attack and achieving their objectives of data theft and credential harvesting. The implications of this vulnerability are severe, potentially leading to widespread data breaches and unauthorized access to sensitive organizational communications.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.