✓ AI-Debiased Article
Rewritten from Ars Technica • • 1 min read
4 Wire-neutral provisional

✓ No loaded language, vague sourcing, or framing detected.

Microsoft warns of exploitation of critical Zimbra vulnerability

Microsoft has issued a warning about a critical vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570, which allows hackers to execute operating system commands remotely without authentication. The vulnerability has led to the compromise of at least 274 instances of the software, with current tracking showing about 10,000 instances still in use.

Companies
Microsoft Synacor

<p>Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite to obtain email backups and authentication credentials of vulnerable organizations, according to a warning from Microsoft.</p><p>The vulnerability, tracked as CVE-2026-73570, allows attackers to remotely issue operating system commands without authentication. Zimbra maintainer Synacor issued a patch on July 20, but did not disclose the vulnerability for more than three weeks after that. The security-focused Shadowserver Foundation reported that its scans found 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks after. Currently, Shadowserver is tracking approximately 10,000 instances.</p><h2>Look, ma, no authorization</h2><p>From July 28 to August 7, Microsoft detected two distinct scanning tools probing the Internet for vulnerable endpoints. The attackers first validated their exploit by sending HTTP requests and DNS, ICMP, and out-of-band identity checks to domains hosted on public services. These probes allowed the attackers to confirm that the exploit successfully executed commands on vulnerable servers without actually compromising them. Eventually, the attackers began using their command injection capability to install malicious payloads. Microsoft stated:</p><p><a href="https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/">Read full article</a></p><p><a href="https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/#comments">Comments</a></p>

Annotating as

No note attached

on this article.

Original vs. Neutral

Original Headline

Attackers have been exploiting critical Zimbra flaw to steal emails

Neutral Headline

Microsoft warns of exploitation of critical Zimbra vulnerability