Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft catches hackers exploiting Zimbra bug before disclosure

Attackers were probing the mail server flaw weeks before it had a CVE to its name

Microsoft catches hackers exploiting Zimbra bug before disclosure

Microsoft identified hackers probing Zimbra mail servers for a critical bug weeks before it was officially disclosed, and subsequently exploited it to steal credentials, raid mailboxes, and gain deeper system control. The vulnerability, CVE-2026-73570, is an unauthenticated command injection flaw that allows attackers to run commands on vulnerable internet-facing servers, provided the optional SNMP monitoring package with notifications is enabled.

Microsoft discovered the exploit on July 28, with attacks occurring between July 28 and August 7. Attackers used common network utilities to identify vulnerable servers, confirm command execution, and deploy web shells and reverse shells for extended access. Some attackers cleaned up by reverting permissions changes, while others probed wider Zimbra environments for additional servers and trusted connections.

One compromised machine resulted in attackers gaining root access and maintaining high-privilege command execution. Microsoft also found attackers targeting Zimbra credentials and authentication secrets, potentially accessed through malicious tools designed to extract service account credentials and pull mailbox information. The company noted affected organizations spanning multiple regions and industries, with attacks ranging from automated exploitation to deliberate manual intervention.

Microsoft advises upgrading to Zimbra 10.1.20 or later and recommends disabling the optional SNMP package or SNMP notifications for those unable to patch.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Thursday 1 October →