Microsoft warns attackers are exploiting critical unauthenticated RCE flaw CVE-2026-73570 in Zimbra Collaboration Suite to steal email backups and credentials
Microsoft published a warning that attackers have been exploiting CVE-2026-73570, an unauthenticated remote command execution flaw in Zimbra Collaboration Suite (via the SNMP notification path when the optional zimbra-snmp package is installed and SNMP notifications are enabled). Microsoft observed scanning from July 28 to August 7, followed by web shell deployment, privilege escalation, and collection of mailbox and credential data. Synacor patched on July 20 (fixed in 10.1.20 or later) but disclosed the flaw about three weeks later. Shadowserver found 274 compromised instances; about 10,000 instances are still tracked as exposed. This is a conventional security vulnerability, not an AI development.
Entities: Zimbra Collaboration Suite, Synacor, Microsoft, Shadowserver Foundation, CVE-2026-73570, Dan Goodin
0 primary
What happened
Microsoft says attackers have been exploiting CVE-2026-73570, an unauthenticated remote command execution flaw in Zimbra Collaboration Suite. It is reachable through the SNMP notification path, and only where the optional zimbra-snmp package is installed and SNMP notifications are enabled. Microsoft saw scanning from 28 July to 7 August, followed by web shell deployment, privilege escalation and collection of mailbox and credential data. Synacor patched on 20 July (version 10.1.20 or later) but disclosed the flaw about three weeks later. Shadowserver found 274 compromised instances and still tracks about 10,000 as exposed.
Why it matters
Anyone running self-hosted Zimbra with SNMP notifications enabled and a version below 10.1.20 should treat the server as potentially compromised, not just unpatched. Attackers took email archives and credentials, so patching alone does not undo the damage. Credentials should be reset and logs checked back to at least late July. The exposure is limited to a non-default configuration, so many Zimbra deployments are not affected. The roughly 10,000 exposed instances is a count of tracked hosts, not a confirmed count of vulnerable ones.
What is noise
The "critical" and "across multiple regions and industries" framing is accurate but generic, and it hides the fact that the flaw needs an optional package and a specific setting. The gap between the 20 July patch and the later disclosure is the real story, and it is about vendor communication, not AI. Nothing here concerns AI, so its place on an AI signal desk is questionable. The extraction lists no primary evidence links, so the Microsoft write-up and Shadowserver figures were not directly verified here.
Watch next
- 01Shadowserver's count of compromised and exposed Zimbra instances over the next few weeks. A steady fall in the 10,000 figure would show patching is happening, and a rise in the 274 compromised would show the campaign is still active.
- 02Whether CISA adds CVE-2026-73570 to its Known Exploited Vulnerabilities catalogue, and whether public proof-of-concept exploit code appears, which would widen the pool of attackers.
- 03Any statement from Synacor or Zimbra explaining the three-week gap between patch and disclosure, and whether further affected configurations or earlier versions are identified beyond the SNMP-enabled case.
Coverage
1 storyMore infrastructure signals
Full feed →- Anthropic commits $11.6B over seven years to Akamai for CPU-focused cloud infrastructure, with warrant tied to spending milestones25 Sept 202688
- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- OpenAI discloses sandbox-escape and credential-leak incidents, confirms pause on tool-use for its most capable models26 Sept 202680
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680