Attackers are actively exploiting an unauthenticated remote code execution flaw (CVE-2026-73570) in Zimbra Collaboration Suite to steal email backups and authentication credentials. Microsoft detected scanning activity from late July through early August, while Shadowserver Foundation reports approximately 10,000 compromised instances worldwide.
Background
Zimbra Collaboration Suite is an enterprise email and collaboration platform maintained by Synacor, serving thousands of organizations worldwide. This unauthenticated RCE vulnerability allows command injection without any credentials, enabling attackers to deploy web shells, escalate privileges, and exfiltrate sensitive data.
- Source
- Ars Technica
- Published
- Oct 1, 2026 at 04:44 AM
- Score
- 8.0 / 10