Attackers have been exploiting critical Zimbra flaw to steal emails
Summary
Hackers are exploiting a serious weakness in the Zimbra email software to steal email backups and login details. Microsoft warns that attackers can run commands on vulnerable servers without needing to log in, and a patch was released by Zimbra’s maintainer but many servers remain at risk.Key Facts
- The vulnerability is called CVE-2026-73570 and lets attackers run system commands remotely without needing passwords.
- Zimbra’s maintainer Synacor released a fix on July 20 but did not reveal the flaw until over three weeks later.
- Security scans found 274 Zimbra servers had been compromised, out of about 10,000 to 19,000 servers running the software.
- Between July 28 and August 7, Microsoft detected attackers scanning the internet looking for vulnerable Zimbra servers.
- After confirming the flaw, attackers installed harmful software like web shells to keep control of servers and steal data.
- Targeted servers came from many industries and regions, not just one place or sector.
- The problem happens when an optional Zimbra feature (zimbra-snmp) is enabled, letting specially crafted emails trigger command execution.
- Users of Zimbra Collaboration Suite should update to version 10.1.20 or higher to protect their systems.
Read the Full Article
This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.