A Zimbra bug patched in July is still letting attackers break into email servers months later.
The flaw, tracked as CVE-2026-73570, lets anyone send unauthenticated commands straight to the operating system running Zimbra Collaboration Suite. Synacor, which maintains Zimbra, shipped a fix on July 20 but didn't publicly disclose the bug for more than three weeks after that. Microsoft says that between July 28 and August 7, two distinct scanning tools swept the internet for vulnerable servers, first firing off HTTP, DNS, ICMP, and out-of-band checks just to confirm the exploit worked without actually touching a target. Once attackers had that confirmation, they switched to using the command injection bug to drop real payloads aimed at email backups and login credentials.
This isn't a zero-day story; it's a disclosure-gap one. Synacor's quiet three-week window between patching and announcing gave slow-moving IT teams no signal to prioritize the update, and attackers used exactly that silence to build and test their tooling before striking. Email servers are an efficient target because one breach can hand over years of correspondence plus the credentials needed to pivot further into an organization.
Shadowserver counts 274 compromised instances among the roughly 10,000 Zimbra servers still reachable online, down from 19,000 right after the patch shipped. That's progress, but still a lot of open doors for a bug that's been fixable since July.