Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned. The vulnerability, tracked as CVE-2026-73570, lets attackers remotely issue operating system commands without authentication. Zimbra maintainer Synacor issued a patch on July 20, but didn’t disclose the vulnerability for more than three weeks after that.
Attackers have been exploiting critical Zimbra flaw to steal emails
About this summary. This is a short, independently written summary of an article first published by Ars Technica. Cyber Security News did not report or verify the underlying story. Read the original: https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/

Source attribution: headline and facts are from Ars Technica (arstechnica.com). Summary method: excerpt of the source description. See our source attribution policy.






