Microsoft has warned that hackers exploited a critical vulnerability in Zimbra Collaboration Suite to obtain email backups and authentication credentials from affected organizations. The flaw, tracked as CVE-2026-73570, allows attackers to issue operating system commands remotely without authentication.
The vulnerability activates when a crafted SMTP request targets the ZCS SNMP notification path. This requires an optional `zimbra-snmp` package to be installed and SNMP notifications enabled. Without input sanitization, embedded shell commands execute with the privileges of the zimbra service account.
Zimbra maintainer Synacor issued a patch for CVE-2026-73570 on July 20 but did not publicly disclose the vulnerability for more than three weeks after release.
The Shadowserver Foundation reported finding 274 separate instances of Zimbra Collaboration Suite that had been compromised. The number of servers running the software fluctuated from 19,000 in the week following the patch to approximately 12,000 in subsequent weeks. Currently, Shadowserver tracks about 10,000 active instances.
From July 28 to August 7, Microsoft detected two distinct scanning tools probing the internet for vulnerable endpoints. Attackers first validated their exploit by sending HTTP requests and DNS, ICMP, and out-of-band identity checks to public services. These probes confirmed command execution on vulnerable servers.
Following successful validation, attackers deployed JSP web shells, reverse shells, privilege escalation tools, and memory-backed execution mechanisms. Threat actors accessed email, collected authentication and mailbox data, and created archives for transfer. Microsoft could not verify whether the attackers successfully exfiltrated the data.
Operations included both automated payload delivery and hands-on-keyboard activity on compromised mail servers. Affected organizations span multiple regions and industries, indicating the exploitation was opportunistic rather than sector-specific.
Microsoft provided no details on the attackers' identity or whether they were nation-state actors or financially motivated criminals.
Synacor's three-week disclosure delay after issuing a patch created a critical window where customers faced active exploitation without awareness or guidance. For enterprise software vendors, delayed public disclosure after a patch is available erodes customer trust and increases operational costs for organizations managing security risks without full information.
