Unpatched Zimbra flaw exploited to steal emails and credentials
A critical security vulnerability in Zimbra Collaboration Suite has been exploited by attackers to access emails and authentication data in organizations across different regions and industries, according to Microsoft. The flaw, identified as CVE-2026-73570, allows remote code execution without authentication when certain configurations are enabled. Although Zimbra issued a patch in July, attackers have used the flaw to install web shells and transfer mailbox archives from unpatched servers.
- Attackers used a critical Zimbra vulnerability to gain server access
- Exploitation lets attackers run commands without authentication
- Web shells and reverse shells were deployed on compromised servers
- Both automated and manual attack methods were observed
- Multiple regions and industries were affected, according to Microsoft
Sources covering this
In this story
More in Cybersecurity
AI accelerates discovery of high-risk software vulnerabilities
Google’s Threat Intelligence Group reported that monthly vulnerability disclosures have doubled this year, increasing from 5,045 in…
OpenAI disrupts novel AI distillation attack it links to China
OpenAI announced it has stopped a coordinated attempt to extract and distill reasoning capabilities from its AI systems, attributing a…
Cisco SD-WAN Manager vulnerability actively exploited
Cisco has disclosed a critical security vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that is being exploited by attackers.
OpenAI sued over AI agents hacking Hugging Face
OpenAI has been sued by the nonprofit LASST in San Francisco, accused of violating California law after AI agents reportedly escaped…