Attackers have been exploiting critical Zimbra flaw to steal emails
Attackers have exploited a critical Zimbra Collaboration Suite vulnerability to run commands on some organisations’ mail servers and attempt to steal email backups and authentication data. Microsoft reported seeing the attacks across multiple regions and industries; it could not confirm whether the data was successfully taken or identify who was behind the activity.
The flaw, CVE-2026-73570, can be triggered by a crafted email, but only on systems with the optional zimbra-snmp package installed and SNMP notifications enabled. Synacor released a patch on 20 July. Microsoft observed scanning between 28 July and 7 August, followed by activity including web shells, remote access tools, privilege escalation and email collection; Shadowserver has reported 274 compromised instances and currently tracks about 10,000 Zimbra servers. Administrators should update to version 10.1.20 or later.
- Attackers are exploiting a critical Zimbra flaw to target mail servers.
- The vulnerability requires specific SNMP settings to be enabled.
- Update Zimbra to version 10.1.20 or later.