Zimbra flaw CVE-2026-73570 exploited to steal emails, Microsoft says
Microsoft reports that attackers have been actively exploiting a critical unauthenticated command-injection vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570, to access and exfiltrate email and credential data. Synacor patched the flaw on July 20 but did not publicly disclose it for over three weeks, and the Shadowserver Foundation found 274 compromised instances among roughly 10,000 servers still running the software. Microsoft observed attackers scanning for vulnerable servers, confirming exploitation, then deploying web shells, reverse shells, and persistence tools before accessing and archiving mailbox data for transfer.