Skip to content
Tech News
← Back to articles

Zimbra flaw CVE-2026-73570 exploited to steal emails, Microsoft says

read original get YubiKey 5 NFC Security Key → more articles
GoKawiil Brief

Microsoft reports that attackers have been actively exploiting a critical unauthenticated command-injection vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570, to access and exfiltrate email and credential data. Synacor patched the flaw on July 20 but did not publicly disclose it for over three weeks, and the Shadowserver Foundation found 274 compromised instances among roughly 10,000 servers still running the software. Microsoft observed attackers scanning for vulnerable servers, confirming exploitation, then deploying web shells, reverse shells, and persistence tools before accessing and archiving mailbox data for transfer.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The delayed disclosure window between patching and public warning likely gave attackers extra time to identify and compromise vulnerable servers before defenders could act, according to the timeline Microsoft and Shadowserver describe. Because Zimbra hosts corporate email, successful exploitation could expose sensitive communications and credentials across multiple industries and regions, Microsoft notes. The mix of automated scanning and hands-on-keyboard activity suggests attackers are both opportunistic and capable of sustained, targeted intrusions once inside.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — With attackers actively harvesting authentication credentials from vulnerable email servers like Zimbra, hardware-based multi-factor authentication is one of the strongest defenses you can add to protect accounts even if passwords leak. A YubiKey lets you enforce phishing-resistant login for email and admin portals, which is exactly the kind of protection that would blunt credential-theft attacks like the one described in this article.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: arstechnica.com, 2026-09-30

Published there as: “Attackers have been exploiting critical Zimbra flaw to steal emails”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.