Key facts
- A critical vulnerability, CVE-2026-73570, is being exploited in Zimbra Collaboration Suite.
- The flaw allows remote attackers to execute operating system commands without authentication.
- A patch was issued by Synacor on July 20.
- Shadowserver Foundation identified 274 compromised Zimbra instances.
- Microsoft observed exploitation activities including deployment of web shells and data theft.
Hackers are actively exploiting a critical vulnerability in the Zimbra Collaboration Suite, a widely used email and collaboration platform, to steal sensitive data including email backups and authentication credentials. Microsoft issued a warning about the ongoing exploitation of the flaw, tracked as CVE-2026-73570.
The vulnerability allows attackers to remotely execute operating system commands without requiring any authentication. While Zimbra maintainer Synacor released a patch on July 20, the vulnerability was not disclosed for over three weeks. Security firm Shadowserver Foundation reported that its scans detected 274 separate instances of the Zimbra Collaboration Suite that had already been compromised.
Microsoft observed that from July 28 to August 7, attackers used two distinct scanning tools to probe the internet for vulnerable servers. Initially, these tools were used to validate the exploit by sending HTTP requests and DNS, ICMP, and out-of-band identity checks. This allowed attackers to confirm command execution on vulnerable servers without fully compromising them. Subsequently, the attackers began deploying malicious payloads.
Following successful exploitation, observed activities included the deployment of JSP web shells and reverse shells, privilege escalation, installation of persistent remote-access tools, and memory-backed execution. Threat actors also gained access to emails and collected authentication and mailbox data, with evidence of archive creation and subsequent transfer. Microsoft noted that affected organizations spanned multiple regions and industries, indicating the exploitation was not geographically or sectorally limited.
