Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft catches hackers exploiting Zimbra bug before disclosure

Attackers were probing the mail server flaw weeks before it had a CVE to its name

Microsoft catches hackers exploiting Zimbra bug before disclosure

Microsoft's Threat Intelligence team discovered hackers probing Zimbra mail servers for a critical vulnerability weeks before the flaw was officially disclosed. The security flaw, CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite, allows attackers to execute commands on exposed mail servers without needing stolen passwords.

Microsoft found scans probing the server shortly after the flaw was patched in Zimbra version 10.1.20, on July 20, but the vulnerability remained undisclosed until August 13. The attackers started by identifying vulnerable servers and testing the flaw, then deployed web shells and reverse shells to gain deeper control of compromised systems.

Some attackers even restored original settings to make their activities harder to detect. They targeted mailboxes, credentials, and authentication secrets, in some cases even escalating their privileges to root access. Microsoft advises affected organizations to update to the patched version or disable the optional SNMP package to reduce exposure.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Thursday 1 October →