Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Critical Zimbra Vulnerability Allows Remote Attackers to Steal Emails and Data


A critical vulnerability in the Zimbra Collaboration Suite has been exploited by hackers to steal emails and data, with Microsoft detecting over 10,000 affected servers. Organizations running the software are advised to patch their systems and take measures to prevent exploitation.

  • Microsoft has exposed a critical vulnerability in the Zimbra Collaboration Suite, allowing attackers to remotely issue operating system commands without authentication.
  • The vulnerability (CVE-2026-73570) allows attackers to steal emails, data, and create email backups.
  • The flaw is tied to the ZCS SNMP notification path and can be exploited by sending a specially crafted SMTP request.
  • Microsoft has recommended patching systems running version 10.1.20 or later and providing guidance to lock down systems to prevent exploitation.
  • Organizations running ZCS software should take immediate action to patch their systems and ensure the security of their email servers.



  • A recent discovery by Microsoft has exposed a critical vulnerability in the Zimbra Collaboration Suite, a widely used email server software. The vulnerability, tracked as CVE-2026-73570, allows attackers to remotely issue operating system commands without authentication, effectively giving them the ability to steal emails, data, and even create email backups. This critical flaw has been exploited by hackers to compromise thousands of instances of the Zimbra Collaboration Suite, with Microsoft detecting over 10,000 affected servers as of recent scans.

    The vulnerability is tied to the ZCS SNMP notification path, which is only triggered when an optional zimbra-snmp package is present and SNMP notifications are enabled. An attacker can send a specially crafted SMTP request that introduces untrusted input into SNMP notification processing, allowing embedded shell commands to execute with the privileges of the zimbra service account. Once inside, the attackers can install web shells, use them to issue commands, and collect email backups and authentication credentials.

    Microsoft warned that the attackers observed went on to use their newfound privileges to deploy JSP web shells, reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution. The company also observed the attackers accessing email, collecting authentication and mailbox data, and even creating archive creation and subsequent transfer activity. The attacks have been observed in more than one region and industry, with Microsoft noting that exploitation was not limited to a single sector or geographic area.

    Microsoft has provided guidance for organizations running the Zimbra Collaboration Suite, recommending that they ensure they are running version 10.1.20 or later. The company has also issued other advice for locking down systems to prevent exploitation.

    In light of this critical vulnerability, anyone responsible for maintaining ZCS software should take immediate action to patch their systems and ensure the security of their email servers. The stakes are high, as the attackers can potentially gain unauthorized access to sensitive data, including emails and authentication credentials.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Critical-Zimbra-Vulnerability-Allows-Remote-Attackers-to-Steal-Emails-and-Data-ehn.shtml

  • https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-73570

  • https://www.cvedetails.com/cve/CVE-2026-73570/


  • Published: Wed Sep 30 16:41:32 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us