Today's AI/ML headlines are brought to you by ThreatPerspective

Digital Event Horizon

Exploiting a Critical Zimbra Flaw: A Threat to Email Security



Microsoft Warns of Critical Zimbra Vulnerability, Hackers Steal Email Backups and Credentials
A recently discovered critical vulnerability in the Zimbra Collaboration Suite has allowed hackers to steal email backups and authentication credentials of vulnerable organizations. Microsoft has warned of the exploit, which can be triggered by a specially crafted email, and has advised users to update to version 10.1.20 or later to prevent exploitation.

  • The recent discovery of a critical vulnerability in the Zimbra Collaboration Suite has been exploited by hackers.
  • The vulnerability, CVE-2026-73570, allows attackers to remotely inject operating system commands, giving them access to sensitive data and systems.
  • The vulnerability can be triggered by a specially crafted email targeting the ZCS SNMP notification path.
  • The attackers have been using the vulnerability to install malicious payloads, such as web shells and reverse shells, on compromised mail servers.
  • The exploit has been detected by Microsoft, which has observed successful exploitation and theft of email backups and authentication credentials.
  • Maintenance of ZCS software version 10.1.20 or later is recommended to prevent exploitation, and Microsoft has provided guidance on how to lock down systems.
  • As of now, Shadowserver Foundation is tracking around 10,000 instances of the Zimbra Collaboration Suite, with 274 separate instances previously compromised.



  • The recent discovery of a critical vulnerability in the Zimbra Collaboration Suite has sent shockwaves through the cybersecurity community. The flaw, tracked as CVE-2026-73570, allows attackers to remotely inject operating system commands, effectively giving them access to sensitive data and systems. This vulnerability has been exploited by hackers, who have been stealing email backups and authentication credentials from vulnerable organizations.

    According to Microsoft, the vulnerability can be triggered by a specially crafted email that targets the ZCS SNMP notification path. However, only when an optional zimbra-snmp package is in place and SNMP notifications are enabled can the attacker gain access to the system. The attacker can then use this access to run operating system commands, which can be used to install malicious payloads, such as web shells and reverse shells.

    The attackers have been using their command injection capability to install these malicious payloads, which have allowed them to deploy JSP web shells and reverse shells on compromised mail servers. This has enabled the attackers to gain persistent remote access to the systems, as well as access to email and authentication data.

    Microsoft has observed that the attackers have been using their access to create email backups and collect credentials. The company has also observed that the attackers have been using their command injection capability to install malicious payloads, which have allowed them to issue commands to create email backups and collect credentials.

    The company has warned that anyone responsible for maintaining ZCS software should ensure they are running version 10.1.20 or later, as this version includes patches to prevent the exploitation of the vulnerability. Microsoft has also provided guidance on how to lock down systems to prevent exploitation.

    Shadowserver Foundation has reported that 274 separate instances of the Zimbra Collaboration Suite had been compromised, with the number of servers running the software fluctuating from 19,000 in the week following the patch to about 12,000 in the weeks following that. Currently, Shadowserver is tracking around 10,000 instances.

    The exploit has been detected by Microsoft, which has detected two distinct scanning tools probing the internet for vulnerable endpoints. The attackers have been using these tools to probe for vulnerable endpoints, and have confirmed that the exploit successfully executed commands on vulnerable servers without actually compromising them.

    The company has warned that the exploit has been successful, and that the attackers have been able to access email and collect authentication and mailbox data. The company has also observed that the attackers have been using their command injection capability to issue commands to create email backups and collect credentials.

    In conclusion, the recent discovery of the critical Zimbra vulnerability has highlighted the importance of keeping software up to date and taking steps to prevent exploitation. The attackers have been able to exploit the vulnerability to steal email backups and authentication credentials, and the company has warned that anyone responsible for maintaining ZCS software should take steps to prevent exploitation.



    Related Information:
  • https://www.digitaleventhorizon.com/articles/Exploiting-a-Critical-Zimbra-Flaw-A-Threat-to-Email-Security-deh.shtml

  • https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/


  • Published: Wed Sep 30 17:31:42 2026 by llama3.2 3B Q4_K_M











    © Digital Event Horizon . All rights reserved.

    Privacy | Terms of Use | Contact Us