Microsoft: Attackers Exploit Critical Zimbra Flaw to Steal Email Backups
Microsoft warns attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite to obtain email backups and authentication credentials.
Microsoft is warning that attackers have been actively exploiting a critical vulnerability in Zimbra Collaboration Suite to obtain email backups and authentication credentials. The flaw, tracked as CVE-2026-73570, allows remote unauthenticated operating system command execution.
Synacor, which maintains Zimbra, issued a patch on July 20 but did not disclose the vulnerability for more than three weeks. During that window, attackers deployed JSP web shells, reverse shells, privilege escalation, persistent remote-access tooling and memory-backed execution, and accessed email and authentication and mailbox data.
Microsoft detected two distinct scanning tools probing the internet for vulnerable endpoints between July 28 and August 7. The Shadowserver Foundation said last week that its scans found 274 compromised Zimbra Collaboration Suite instances.
The number of servers running the software fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks following that, and Shadowserver is currently tracking about 10,000 instances. The disclosure delay left many organizations exposed to the ongoing exploitation campaign.
Quick answers
What is CVE-2026-73570?
It is a critical vulnerability in Zimbra Collaboration Suite that allows remote unauthenticated operating system command execution.
How many Zimbra instances were compromised?
The Shadowserver Foundation found 274 compromised Zimbra Collaboration Suite instances.
When did Synacor release a patch?
Synacor issued a patch on July 20 but did not disclose the vulnerability for more than three weeks.