Attackers have been exploiting critical Zimbra flaw to steal emails
Microsoft has warned that hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570, to obtain authentication credentials and email backups from vulnerable organizations.

Microsoft has warned that hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570, to obtain authentication credentials and email backups from vulnerable organizations. The vulnerability allows unauthenticated remote attackers to inject operating system commands via a crafted email targeting the ZCS SNMP notification path, but only when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
Microsoft stated that between July 28 and August 7, it detected two distinct scanning tools probing the internet for vulnerable endpoints across multiple geographic areas and sectors. Attackers subsequently installed webshells to execute commands for creating email backups and collecting credentials. The Shadowserver Foundation reported last week that scans identified 274 compromised instances of the Zimbra Collaboration Suite out of roughly 10,000 instances it currently tracks.
Microsoft noted it could not verify whether the attackers successfully exfiltrated the targeted data, and the company published guidance for securing affected systems against the vulnerability.
WireUnWired turns the supplied report into a clearer brief, preserves the original publisher and author details, and adds relevant context without hiding where the information came from.
Relevant WireUnWired coverage is connected so one story can lead into the larger technology context.
Original publication: 1 October 2026 02:14



