Critical Zimbra vulnerability exploited to steal emails

Hackers are exploiting a vulnerability in Zimbra to access emails and credentials. Despite a patch being released, many servers remain at risk.
Recently, it has come to light that hackers are exploiting a critical vulnerability in the Zimbra Collaboration Suite, allowing them to execute operating system commands remotely without authentication. The vulnerability, tracked as CVE-2026-73570, led Microsoft to issue a warning about the risk of email backups and authentication credentials being stolen from vulnerable organizations.
Zimbra, maintained by Synacor, released a patch for this vulnerability on July 20, but did not disclose the issue for more than three weeks afterward. This delay has raised concerns, as timely information can be crucial in protecting organizations from potential breaches. According to the Shadowserver Foundation, scans identified 274 compromised instances of Zimbra, highlighting the severity of the situation.
Since the patch was issued, the number of servers running Zimbra has fluctuated significantly. In the week following the patch, there were about 19,000 active servers, but that number has now decreased to around 10,000. This indicates that many organizations have taken steps to mitigate the risk, but others may still be in danger.
It is crucial for organizations using Zimbra to verify whether they are running the affected version and apply the necessary patch. The situation also underscores the importance of maintaining good communication regarding security vulnerabilities, as the speed of information dissemination can be vital in protecting sensitive company data.
Read at the original source:
Ars Technica →Related news
SecurityElder fraud is rising: how to protect your family
Elder fraud is increasing in the U.S., driven by data exposure. Here’s how to keep your loved ones safe.
SecurityLawsuit against OpenAI for Hugging Face hack
A lawsuit demands OpenAI to halt AI development following the Hugging Face hack. This raises concerns about safety in advanced technology usage.
SecurityOpenAI responds to recent hacks and their fallout
OpenAI is facing the repercussions of several recent hacks. Its research chief discusses how the company is managing the situation.