Technologies
Back
Cybersecurity & Privacy

Attackers exploiting critical Zimbra vulnerability to steal sensitive data

Ars Technica
Advertisement468 × 90
Attackers exploiting critical Zimbra vulnerability to steal sensitive data

Microsoft has issued a warning regarding a critical vulnerability, tracked as CVE-2026-73570, affecting the Zimbra Collaboration Suite. The flaw allows unauthorized attackers to execute remote operating system commands on vulnerable servers. While the software maintainer, Synacor, released a patch on July 20, the vulnerability remained undisclosed for several weeks. According to the Shadowserver Foundation, hundreds of instances have already been compromised. Attackers have been observed using automated scanning tools to identify vulnerable endpoints, subsequently deploying malicious payloads to steal email backups and authentication credentials. Microsoft reports that while the number of exposed servers has decreased since the patch release, thousands of instances remain at risk. Organizations using Zimbra are urged to ensure their systems are fully updated to mitigate the threat of unauthorized command injection and potential data exfiltration.

This is a summary. Read the full article at the original source:

Ars Technica
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250