---
title: "Hackers Exploit a Critical Zimbra Flaw to Steal Email Backups and Credentials"
description: "Microsoft says one crafted email can run commands on unpatched servers, and 274 have already been compromised."
author: "rews desk"
published: 2026-09-30T20:44:48Z
modified: 2026-10-01T00:57:35Z
url: https://rews.cc/a/hackers-exploit-a-critical-zimbra-flaw-to-steal-email-backup-6ac0ba
language: en
tags: ["cybersecurity", "zimbra", "ransomware", "microsoft", "vulnerability", "tech"]
publisher: "Rews (https://rews.cc)"
---

# Hackers Exploit a Critical Zimbra Flaw to Steal Email Backups and Credentials

*Microsoft says one crafted email can run commands on unpatched servers, and 274 have already been compromised.*

By rews desk · September 30, 2026 · https://rews.cc/a/hackers-exploit-a-critical-zimbra-flaw-to-steal-email-backup-6ac0ba

## In brief

- Hackers exploited a critical Zimbra Collaboration Suite flaw to steal email backups and credentials, Microsoft said
- The flaw, CVE-2026-73570, runs OS commands without a login, but only if the optional zimbra-snmp package is enabled
- Synacor patched the flaw on July 20 but did not disclose it for more than three weeks
- Shadowserver found 274 compromised Zimbra instances and is tracking about 10,000 exposed servers
- Victims spanned more than one region and industry, with automated and hands-on attacks

Hackers have been exploiting a critical flaw in the Zimbra Collaboration Suite email system since late July to steal email backups and sign-in credentials from vulnerable organizations, Microsoft said on Wednesday.

The vulnerability, tracked as CVE-2026-73570, lets an attacker with no credentials run operating-system commands on a server by sending a crafted email aimed at the suite’s SNMP notification path, according to Microsoft’s report. It works only when an optional component, the zimbra-snmp package, is installed and SNMP notifications are switched on. Ars Technica first reported the campaign.

Synacor, which maintains Zimbra, released a patch on July 20 but did not publicly disclose the vulnerability for more than three weeks after that.

Many servers remain exposed. The Shadowserver Foundation, a security group, said last week that its scans had found 274 separate Zimbra instances already compromised. The group counted about 19,000 servers running the software in the week after the patch and roughly 12,000 in the weeks that followed. It is now tracking about 10,000.

Between July 28 and Aug. 7, Microsoft said, it detected two distinct scanning tools probing the internet for vulnerable systems. The attackers first checked that their exploit worked — sending HTTP requests and DNS, ICMP and other out-of-band identity checks to domains hosted on public services, which confirmed that commands ran on the target servers without actually compromising them. Then they moved to installing malicious payloads.

“Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution,” Microsoft wrote. “Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed.”

The intrusions mixed automated payload delivery with hands-on-keyboard work on compromised mail servers, the company said, and hit organizations in more than one region and industry. “Based on the environments investigated, exploitation was not limited to a single sector or geographic area,” Microsoft said.
