Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Microsoft Discovers Hackers Exploiting Vulnerability in Zimbra Mail Server Prior to Public Disclosure


Microsoft has revealed that it caught hackers exploiting a critical vulnerability in Zimbra's mail server weeks before the vulnerability was publicly disclosed. The vulnerability, identified as CVE-2026-73570, is an unauthenticated command injection vulnerability that could potentially allow attackers to gain access to exposed mail servers without needing stolen passwords or clicking on malicious links. Microsoft has since patched the vulnerability and is advising affected organizations to take action to protect themselves.

  • Microsoft discovered a critical vulnerability in Zimbra's mail server, CVE-2026-73570, weeks before it was publicly disclosed.
  • The vulnerability is an unauthenticated command injection vulnerability that can allow attackers to gain access to exposed mail servers.
  • Attackers exploited the vulnerability by deploying web shells and reverse shells to escalate their privileges.
  • The attackers also targeted user mailboxes, hunting for Zimbra credentials and authentication secrets.
  • Microsoft patched the vulnerability in Zimbra version 10.1.20 and advises admins to update or remove the optional SNMP package.
  • The incident highlights the importance of keeping software up to date and being vigilant about vulnerabilities.



  • Microsoft has revealed that it caught hackers exploiting a critical vulnerability in Zimbra's mail server weeks before the vulnerability was publicly disclosed. The vulnerability, identified as CVE-2026-73570, is an unauthenticated command injection vulnerability that could potentially allow attackers to gain access to exposed mail servers without needing stolen passwords or clicking on malicious links.

    According to Microsoft Threat Intelligence, the company tracked the exploitation of the vulnerability, which was found to be a result of a critical bug in Zimbra's optional SNMP monitoring package with notifications enabled. The attackers used a combination of common network utilities to test the vulnerability and then deployed web shells and reverse shells to escalate their privileges.

    Microsoft said that the attackers also explored the wider Zimbra environments they landed in, identifying other mail servers and looking for trusted connections to move between them. In some cases, they even managed to gain root access to compromised machines, setting up the environment to run commands with the highest privileges without needing a password.

    The attackers also targeted user mailboxes, hunting for Zimbra credentials and authentication secrets that could be used to access user accounts. One malicious tool found by Microsoft was designed specifically to extract service account credentials and pull mailbox information from Zimbra's databases.

    Microsoft revealed that it spotted probes for the flaw more than two weeks before it was publicly disclosed, highlighting the vulnerability to the public domain. The company has since patched the vulnerability in Zimbra version 10.1.20, which is now the recommended update for affected organizations.

    To mitigate the risk, Microsoft advises admins running versions earlier than Zimbra 10.1.20 to update to 10.1.20 or later, or to remove the optional SNMP package or disable SNMP notifications.

    The incident highlights the importance of keeping software up to date and being vigilant about vulnerabilities in common software packages. Microsoft's swift response to the vulnerability demonstrates the company's commitment to protecting its customers from cyber threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Microsoft-Discovers-Hackers-Exploiting-Vulnerability-in-Zimbra-Mail-Server-Prior-to-Public-Disclosure-ehn.shtml

  • https://www.theregister.com/security/2026/10/01/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/5300543

  • https://nvd.nist.gov/vuln/detail/CVE-2026-73570

  • https://www.cvedetails.com/cve/CVE-2026-73570/


  • Published: Thu Oct 1 11:42:30 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us