Barion Pixel

Hackers exploit critical Zimbra flaw to steal emails and credentials

Hackers exploited CVE-2026-73570 to run unauthenticated operating-system commands on Zimbra servers and steal email backups and credentials. Synacor patched the flaw on July 20; scans later identified 274 compromised instances, while about 10,000 deployments remain online.