{
  "id": 11217422,
  "title": "Microsoft catches hackers exploiting Zimbra bug before disclosure",
  "url": "https://urgent.news/2026/10/01/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T14:44:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/01/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/5300543"
  },
  "original_language": "en",
  "account": "Microsoft's Threat Intelligence team discovered hackers probing Zimbra mail servers for a critical vulnerability weeks before the flaw was officially disclosed. The security flaw, CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite, allows attackers to execute commands on exposed mail servers without needing stolen passwords. Microsoft found scans probing the server shortly after the flaw was patched in Zimbra version 10.1.20, on July 20, but the vulnerability remained undisclosed until August 13. The attackers started by identifying vulnerable servers and testing the flaw, then deployed web shells and reverse shells to gain deeper control of compromised systems. Some attackers even restored original settings to make their activities harder to detect. They targeted mailboxes, credentials, and authentication secrets, in some cases even escalating their privileges to root access. Microsoft advises affected organizations to update to the patched version or disable the optional SNMP package to reduce exposure.",
  "summary": "Attackers were probing the mail server flaw weeks before it had a CVE to its name",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Microsoft catches hackers exploiting Zimbra bug before disclosure",
        "url": "https://urgent.news/2026/10/01/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure-11219857",
        "published": "2026-10-01T14:44:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}