Zimbra flaw CVE-2026-73570 exploited to steal emails, Microsoft says
Microsoft reports that attackers have been actively exploiting a critical unauthenticated command-injection vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570, to access and exfiltrate email and credential data. Synacor patched the flaw on July 20 but did not publicly disclose it for over three weeks, and the Shadowserver Foundation found 274 compromised instances among roughly 10,000 servers still running the software. Microsoft observed attackers scanning for vulnerable servers, confirming exploitation, then deploying web shells, reverse shells, and persistence tools before accessing and archiving mailbox data for transfer.
GoKawiil's interpretation of the reporting above, not reported fact.
The delayed disclosure window between patching and public warning likely gave attackers extra time to identify and compromise vulnerable servers before defenders could act, according to the timeline Microsoft and Shadowserver describe. Because Zimbra hosts corporate email, successful exploitation could expose sensitive communications and credentials across multiple industries and regions, Microsoft notes. The mix of automated scanning and hands-on-keyboard activity suggests attackers are both opportunistic and capable of sustained, targeted intrusions once inside.
- CVE-2026-73570 allows unauthenticated remote command execution on Zimbra Collaboration Suite servers.
- Shadowserver found 274 compromised instances out of roughly 10,000 internet-facing Zimbra servers.
- Attackers used scanning tools, web shells, and persistence tools to access and exfiltrate email and credential data.
YubiKey 5 NFC Security Key — With attackers actively harvesting authentication credentials from vulnerable email servers like Zimbra, hardware-based multi-factor authentication is one of the strongest defenses you can add to protect accounts even if passwords leak. A YubiKey lets you enforce phishing-resistant login for email and admin portals, which is exactly the kind of protection that would blunt credential-theft attacks like the one described in this article.
See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: arstechnica.com, 2026-09-30
Published there as: “Attackers have been exploiting critical Zimbra flaw to steal emails”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.