Industry·
Critical Zimbra Flaw Actively Exploited to Steal Email Backups and Credentials
Microsoft confirmed active exploitation of CVE-2026-73570, an unauthenticated command-injection flaw in Zimbra Collaboration Suite that allows attackers to deploy web shells and exfiltrate mail data across multiple sectors and regions.

Microsoft has disclosed that threat actors have been actively exploiting a critical, unauthenticated remote code execution vulnerability in the Zimbra Collaboration Suite (ZCS). The flaw, tracked as CVE-2026-73570, allows an attacker to send a specially crafted SMTP request that injects shell commands through the SNMP notification processing path—provided the optional zimbra-snmp package is installed and SNMP notifications are enabled. No credentials are required.
Synacor, the Zimbra maintainer, released a patch on July 20, 2026, but did not publicly disclose the vulnerability for more than three weeks. During the window between patch release and disclosure, Microsoft observed two distinct scanning tools probing the internet for vulnerable endpoints from July 28 to August 7. After confirming exploitability, attackers moved to deploy JSP web shells, reverse shells, and persistent remote-access tooling on compromised servers.
Observed attacker activity
Post-exploitation activity included privilege escalation, memory-backed execution, and collection of authentication and mailbox data. Attackers created email archive backups and initiated transfer activity, consistent with data exfiltration. Microsoft noted that affected organizations spanned multiple regions and industries, and that operations included both automated payload delivery and hands-on-keyboard activity. The Shadowserver Foundation independently confirmed that at least 274 ZCS instances had been compromised, with roughly 10,000 instances still running the software globally.
Microsoft did not attribute the campaign to a specific threat actor or confirm whether data was successfully exfiltrated. The company urged all ZCS administrators to verify they are running version 10.1 or later and to audit for signs of compromise, including unexpected web shell files and anomalous outbound connections.
Why it matters for GPU / AI infrastructure: Many organizations running AI workloads on cloud or on-prem GPU clusters rely on the same email and identity infrastructure for MFA, API key delivery, and internal communications. A compromised mail server can become a pivot point for lateral movement into compute environments. Ensuring all ancillary systems—including mail, SNMP, and directory services—are patched and monitored is a baseline requirement for protecting AI infrastructure investments.
- aigpu
- ai gpu
- ai gpu cloud
- aigpu dubai
- zimbra vulnerability
- cve-2026-73570
- email security
- infrastructure security
By AiGpu Editorial · Editorial rewrite based on public reporting (Ars Technica)
← All articles