Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Critical flaw in Zimbra software exposed to let attackers steal email contents

Hackers exploit a critical Zimbra flaw to steal emails. A fix exists, but many servers remain exposed.

By mitch·4 min read
An illustration of a cracked computer screen revealing email icons amid dark tones, symbolizing a breached system.

Hackers have been exploiting a serious weakness in the Zimbra Collaboration Suite to get hold of email backups and passwords of vulnerable groups, Microsoft has warned.

The weakness, tracked as CVE-2026-73570, lets attackers send operating system commands from afar without needing any password. Zimbra keeper Synacor issued a fix on July 20, but did not tell anyone about the weakness for more than three weeks after that. The security-focused Shadowserver Foundation said last week that its scans found 274 separate cases of the Zimbra Collaboration Suite had been taken over. The number of servers running the software has moved from 19,000 in the week following the fix to about 12,000 in the weeks after that. Right now, Shadowserver is watching about 10,000 cases.

Look, ma, no authorization

From July 28 to August 7, Microsoft said Wednesday, the company saw two separate scanning tools looking across the Internet for weak endpoints. The attackers first checked that their trick worked by sending HTTP requests and DNS, ICMP, and out-of-band identity checks to domains sitting on public services. These checks let the attackers confirm the trick sent commands on weak servers without actually taking them over. Finally, the attackers started using their command injection power to put in bad software.

Advertisement

What the fix does

The fix, issued on July 20, addresses the weakness. Zimbra keeper Synacor made it available, but waited more than three weeks before telling anyone about the problem. That delay means some groups did not know they were weak until Shadowserver’s scans showed them. The fix was made available on July 20, but Synacor did not announce it publicly until more than three weeks later.

The attack chain

The attack follows a clear chain. An attacker sends a specially made email to a server running Zimbra. That email triggers the SNMP notification path, which is set up to accept commands. Because the zimbra-snmp package is present and SNMP notifications are turned on, the server obeys the command without asking for a password.

Once the server is obeying commands, the attacker can do almost anything. The Microsoft report lists several steps the attackers took:

  • Putting in JSP web shells and reverse shells, which give the attacker a steady link back into the server
  • Escalating privileges, giving the attacker higher access within the system
  • Setting up lasting tools for getting into the server from afar
  • Running commands in memory, which hides the evidence of the attack
  • Collecting email and passwords from the server itself
  • Building archives of the stolen data and moving them off the server

The attack also mixes automatic tools with hands-on work. Some parts of the campaign put in software without human help, while other parts required a person sitting at a keyboard on the compromised server. Microsoft said affected groups were hit across more than one region and industry.

How the attackers checked their work

The attackers did not guess. They confirmed each step before moving to the next. The HTTP requests and DNS, ICMP, and out-of-band identity checks proved the trick worked without actually taking over the server. Only after that confirmation did they start putting in software.

That method is deliberate. It saves time and avoids wasting effort on servers that do not respond. The attackers knew exactly which servers were weak before they committed to the full attack. The checks covered HTTP requests, DNS, ICMP, and out-of-band identity checks, and they confirmed the trick worked without actually taking over the server.

The numbers so far

Shadowserver’s scans show the scale of the exposure. In the week after the fix, 19,000 servers were still weak. By the weeks after that, that number had dropped to about 12,000. Right now, Shadowserver is watching about 10,000 cases.

The pattern suggests a slow rollout. Groups are applying the fix, but not fast enough to stop all attacks. The remaining 10,000 servers are still exposed. The number of exposed servers has dropped from 19,000 in the week following the fix to about 12,000 in the weeks after that, with Shadowserver currently watching about 10,000 cases.

What groups should check

Groups running Zimbra should check two things immediately. First, is the zimbra-snmp package present on any server? Second, are SNMP notifications turned on?

If both answers are yes, the server is still weak. The fix is available. If the package is not present, the server is likely safe from this particular weakness. But no group should assume safety. The remaining 10,000 servers are proof that the threat is not over.

The bottom line

The Zimbra weakness is fixed, but the damage is done. The attackers moved fast, and the remaining 10,000 weak servers are a reminder that the threat is not over.

Groups should act now. Check for the zimbra-snmp package. Turn off SNMP notifications if they are not needed. Apply the fix without delay. The attackers have shown what they can do.

Source material: “Attackers have been exploiting critical Zimbra flaw to steal emails,” Ars Technica.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.