Executive Summary
Facts Only
* The vulnerability is tracked as CVE-2026-73570.
* The vulnerability allows remote attackers to issue operating system commands without authentication.
* Zimbra maintainer Synacor issued a patch on July 20.
* The vulnerability was not disclosed for more than three weeks after the patch release.
* Scans found 274 separate instances of the Zimbra Collaboration Suite compromised.
* The number of servers running the software fluctuated from 19,000 to 12,000 following the patch.
* From July 28 to August 7, two scanning tools probed for vulnerable endpoints using HTTP, requests, DNS, ICMP, and out-of-band identity checks.
* Exploitation included deploying JSP web shells, reverse shells, privilege escalation tooling, and memory-backed execution.
* Threat actors accessed email and collected authentication/mailbox data, observing archive creation and transfer.
* The vulnerability exists when an optional zimbra-snmp package is present and SNMP notifications are enabled.
Full Take
From the original · Ars Technica Security
Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned. The vulnerability, tracked as CVE-2026-73570, lets attackers remotely issue operating system commands without authentication.Read the full story at arstechnica.com
Sentinel — Human
The text reads like a factual security advisory, detailing an exploit and subsequent detection, suggesting human compilation of technical and organizational data.
