Attackers Exploit Critical Zimbra Flaw to Steal Email Backups and Credentials
Microsoft warns that attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite to steal email backups and authentication credentials. Synacor patched the flaw on July 20 but delayed disclosure for more than three weeks; Shadowserver has identified 274 compromised instances.
The flaw, tracked as CVE-2026-73570, allows attackers to remotely issue operating system commands without authentication. Zimbra maintainer Synacor released a patch on July 20 but did not disclose the vulnerability for more than three weeks afterward, Ars Technica reported.
The Shadowserver Foundation said last week that its scans found 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated sharply since the patch, falling from 19,000 in the week following its release to about 12,000 in the weeks after that. Shadowserver is currently tracking about 10,000 instances.
Microsoft said Wednesday that between July 28 and August 7 it detected two distinct scanning tools probing the internet for vulnerable endpoints. The scanning began eight days after Synacor issued its patch and while the vulnerability remained undisclosed.
According to Microsoft, the attackers first validated that their exploit worked by sending HTTP requests and DNS, ICMP and out-of-band identity checks to domains hosted on public services. Those probes allowed the attackers to confirm the exploit successfully executed commands on vulnerable servers without actually compromising them. Eventually, the attackers began using their command injection capability to install malicious payloads, Microsoft wrote in its warning.