[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-microsoft-says-patched-zimbra-flaw-was-exploited-in-the-wild":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},8840,"microsoft-says-patched-zimbra-flaw-was-exploited-in-the-wild","Microsoft Says Patched Zimbra Flaw Was Exploited in the Wild","Hackers probed Zimbra servers for weeks before exploiting a command injection flaw Synacor had quietly patched days earlier, Microsoft says.","A Zimbra bug patched in July is still letting attackers break into email servers months later.\n\nThe flaw, tracked as CVE-2026-73570, lets anyone send unauthenticated commands straight to the operating system running Zimbra Collaboration Suite. Synacor, which maintains Zimbra, shipped a fix on July 20 but didn't publicly disclose the bug for more than three weeks after that. Microsoft says that between July 28 and August 7, two distinct scanning tools swept the internet for vulnerable servers, first firing off HTTP, DNS, ICMP, and out-of-band checks just to confirm the exploit worked without actually touching a target. Once attackers had that confirmation, they switched to using the command injection bug to drop real payloads aimed at email backups and login credentials.\n\nThis isn't a zero-day story; it's a disclosure-gap one. Synacor's quiet three-week window between patching and announcing gave slow-moving IT teams no signal to prioritize the update, and attackers used exactly that silence to build and test their tooling before striking. Email servers are an efficient target because one breach can hand over years of correspondence plus the credentials needed to pivot further into an organization.\n\nShadowserver counts 274 compromised instances among the roughly 10,000 Zimbra servers still reachable online, down from 19,000 right after the patch shipped. That's progress, but still a lot of open doors for a bug that's been fixable since July.","[\"zimbra\",\"vulnerabilities\",\"email-security\",\"microsoft\"]","2026-09-30T20:44:48.000Z","2026-10-01T06:32:35.860Z","2026-10-01T06:32:41.892Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The headline calls this a 'Zero Day' but the body itself establishes Synacor shipped a patch on July 20, over a week before Microsoft observed exploitation beginning July 28 — that makes it a known, patched (n-day) vulnerability exploited during a disclosure gap, not a zero-day; fix the headline\u002Fdek to avoid contradicting the article's own reporting.","resolved","security",[32,33,34,35],"zimbra","vulnerabilities","email-security","microsoft",[37],{"name":38,"url":39},"Ars Technica","https:\u002F\u002Farstechnica.com\u002Fsecurity\u002F2026\u002F09\u002Fattackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails\u002F",0,{"sections":42},[43,48,52,57,62,67,72,77,82,86,91,96,101,106],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",5271,"2026-10-01T04:00:00.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":51},"Security",801,"2026-09-30T22:18:23.000Z",{"name":53,"slug":54,"count":55,"latest_published_at":56},"Policy","policy",429,"2026-10-01T02:26:17.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":61},"Deals","deals",298,"2026-09-30T21:00:26.000Z",{"name":63,"slug":64,"count":65,"latest_published_at":66},"Hardware","hardware",196,"2026-09-30T13:00:00.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Science","science",157,"2026-09-30T15:00:56.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":76},"Consumer Tech","consumer-tech",149,"2026-09-30T22:57:11.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Dev Tools","dev-tools",93,"2026-10-01T02:30:48.000Z",{"name":83,"slug":84,"count":80,"latest_published_at":85},"Software","software","2026-09-30T21:41:11.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Startups","startups",84,"2026-09-30T20:39:09.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Gaming","gaming",51,"2026-09-30T16:24:30.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"General","general",50,"2026-09-30T21:37:54.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"Reviews","reviews",31,"2026-09-28T14:31:34.000Z",{"name":107,"slug":108,"count":109,"latest_published_at":110},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]