HeadlinesBriefing HeadlinesBriefing.com

Microsoft Warns Of Active Zimbra Email Server Exploits

Ars Technica •
×

Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite to steal emails and authentication credentials. Microsoft warns that CVE-2026-73570 allows remote attackers to issue operating system commands without authentication. Zimbra maintainer Synacor issued a patch on July 20, but did not disclose the flaw for over three weeks.

Security researchers at the Shadowserver Foundation report that 274 separate instances of the Zimbra Collaboration Suite have been compromised. The number of vulnerable servers has fluctuated significantly, dropping from approximately 19,000 in the week following the patch to about 12,000, and currently tracking around 10,000 instances. From July 28 to August 7, Microsoft detected two distinct scanning tools probing the Internet for vulnerable endpoints.

Attackers first validated their exploit by sending HTTP, DNS, ICMP, and out-of-band identity checks to confirm command execution. Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, and persistent remote-access tooling. Threat actors accessed email data and collected authentication credentials, with archive creation and transfer activity observed.

The attacks affected organizations across multiple regions and industries, involving both automated payload delivery and hands-on-keyboard operations. Exploitation leverages the ZCS SNMP notification path when the optional zimbra-snmp package is installed and SNMP notifications are enabled.

Source: Ars Technica · Summarized by HeadlinesBriefing