The Actual News

Stay informed without the news wearing you out.

Attackers have been exploiting critical Zimbra flaw to steal emails

Attackers have been exploiting critical Zimbra flaw to steal emails

Summary

Hackers are exploiting a serious weakness in the Zimbra email software to steal email backups and login details. Microsoft warns that attackers can run commands on vulnerable servers without needing to log in, and a patch was released by Zimbra’s maintainer but many servers remain at risk.

Key Facts

  • The vulnerability is called CVE-2026-73570 and lets attackers run system commands remotely without needing passwords.
  • Zimbra’s maintainer Synacor released a fix on July 20 but did not reveal the flaw until over three weeks later.
  • Security scans found 274 Zimbra servers had been compromised, out of about 10,000 to 19,000 servers running the software.
  • Between July 28 and August 7, Microsoft detected attackers scanning the internet looking for vulnerable Zimbra servers.
  • After confirming the flaw, attackers installed harmful software like web shells to keep control of servers and steal data.
  • Targeted servers came from many industries and regions, not just one place or sector.
  • The problem happens when an optional Zimbra feature (zimbra-snmp) is enabled, letting specially crafted emails trigger command execution.
  • Users of Zimbra Collaboration Suite should update to version 10.1.20 or higher to protect their systems.
Read the Full Article

This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.

Monday's biggest stories, one calm email.