📣 Skicka ert pressmeddelande till oss
Webbplatsen uppdateras var 15:e minut
Teknologi

Attackers have exploited critical Zimbra flaw to steal emails

Attackers have exploited a critical vulnerability in Zimbra Collaboration Suite to steal email backups and authentication credentials, Microsoft has warned.

30 september 2026
Attackers have exploited critical Zimbra flaw to steal emails

Attackers have exploited a critical vulnerability in Zimbra Collaboration Suite (CVE-2026-73570) in an attempt to steal email backups and organizational authentication credentials, Microsoft has warned.

The vulnerability allows for remote execution of operating system commands without authentication. Zimbra maintainer Synacor released a patch on July 20, but did not disclose the vulnerability for over three weeks afterward.

According to the security organization Shadowserver Foundation, its scans found 274 compromised Zimbra instances. The number of servers running the software has fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks that followed. Shadowserver is currently tracking approximately 10,000 servers.

Microsoft detected two distinct scanning tools between July 28 and August 7 that probed the internet for vulnerable endpoints. Attackers eventually began using their command injection capability to install malicious payloads.

Ursprunglig källa: arstechnica.com