Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Hackers Exploit Critical Zimbra Flaw to Harvest Email Backups and Credentials

Cyber attackers are leveraging a severe vulnerability in Zimbra Collaboration Suite to steal email backups and login data, Microsoft reports.

A critical remote-code-execution bug in Zimbra Collaboration Suite, catalogued as CVE-2026-73570, is being abused to extract email backups and authentication credentials from affected organizations. The vulnerability allows attackers to run operating-system commands without any credentials by sending a specially crafted email that exploits the SNMP notification path, but only when the optional zimbra-snmp component is installed and enabled.

Synacor issued a fix on July 20, yet the flaw was not publicly disclosed for more than three weeks. Shadowserver’s monitoring identified 274 compromised instances, with the total number of servers running Zimbra falling from about 19,000 shortly after the patch to roughly 10,000 in subsequent weeks, and about 10,000 still being tracked. Microsoft detected two scanning tools probing for vulnerable hosts between July 28 and August 7, confirming exploit success before deploying malicious payloads such as JSP web shells, reverse shells, and persistent remote-access tools. The attackers also accessed mailboxes, created archives, and transferred data, operating across multiple regions and industry sectors.

Why it matters

The exploit threatens millions of email accounts, exposing sensitive communications and credentials across many organizations.

In this story

CVE-2026-73570Zimbra Collaboration Suiteemail backup theftremote code executionweb shellsSNMP notificationsecurity patchcyberattackcredential harvesting
Get the beta ↗