arstechnica.com 30 Sept 2026, 20:44 UTC

Attackers Exploit Zimbra Flaw to Steal Emails and Authentication Data

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

ATTACKERS have been exploiting a critical flaw in Zimbra Collaboration Suite to steal emails and back up authentication data. The vulnerability, CVE-2026-73570, allows remote, unauthenticated command execution via a crafted email that targets the ZCS SNMP notification path, but only if the optional zimbra-snmp package is installed and SNMP notifications are enabled. Microsoft described the exploit as enabling attackers to run OS commands through the SNMP notification processing when input is not properly sanitised.

After initial access, observed activity included installing JSP web shells and reverse shells, escalating privileges, maintaining long‑term remote access, and performing memory‑backed execution. The attackers reportedly accessed email and gathered authentication and mailbox data, with archive creation and transfer activity noted, though Microsoft could not confirm data exfiltration.

Evidence from monitoring organisations and industry trackers shows broad impact. Synacor released a patch on 20 July, but details were not disclosed for more than three weeks. Shadowserver Foundation said its scans found 274 compromised Zimbra instances; the active base of Zimbra installations fluctuated, from about 19,000 in the week after the patch to roughly 12,000 in the following weeks, and Shadowserver currently tracks around 10,000 instances.

Microsoft said exploitation has affected organisations across regions and sectors, with activity observed in multiple geographies. In response, administrators should ensure Zimbra is updated to version 10.1.20 or later and follow Microsoft guidance for tightening exposure and lock‑down measures.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline