Attackers have been exploiting critical Zimbra flaw to steal emails
A simple email gives the attackers the ability to remotely inject OS commands.

A simple email gives the attackers the ability to remotely inject OS commands.
The short version
- Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned .
- CVE-2026-73570 allows remote attackers with no credentials to run operating system commands through a crafted email that targets the ZCS SNMP notification path but only when an optional zimbra-snmp package is in place and SNMP notifications are enabled.
- “An attacker can send a specially crafted SMTP request that introduces untrusted input into SNMP notification processing,” Microsoft explained.
What happened
The company said it had no means to verify that the attackers successfully exfiltrated that data. Microsoft provided no details about who the attackers were or whether they were nation-state actors or financially motivated criminals.
Why it matters
Anyone responsible for maintaining ZCS software should ensure they’re running version 10.1.20 or later.
Summary by Nerd News Network. Read the full article at Ars Technica via the links above and below.
