Home / Technology / Microsoft Warns: Hackers Exploit Zimbra Vulnerability
Microsoft Warns: Hackers Exploit Zimbra Vulnerability
1 Oct
Summary
- Hackers exploit CVE-2026-73570 to steal email backups and credentials.
- Vulnerability allows remote OS command execution without authentication.
- Microsoft observed attackers deploying web shells and reverse shells.

Microsoft has alerted organizations to a critical vulnerability in the Zimbra Collaboration Suite, identified as CVE-2026-73570. Hackers are actively exploiting this flaw to gain unauthorized access to email backups and sensitive authentication credentials.
The vulnerability permits remote attackers to execute operating system commands without requiring any authentication. This exploit targets the ZCS SNMP notification path, but only when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
Microsoft observed attackers exploiting this vulnerability to deploy malicious payloads, including JSP web shells and reverse shells. They also engaged in privilege escalation and installed persistent remote-access tools. Observed activities included the creation and transfer of email archives and the collection of mailbox data and credentials.
While Zimbra released a patch on July 20, its maintainer, Synacor, did not disclose the vulnerability for over three weeks. As of the warning, hundreds of Zimbra instances had been compromised, with ongoing scanning detected from July 28 to August 7. Affected organizations spanned multiple regions and industries.