# Attackers exploit critical Zimbra flaw to steal emails

https://mins.news/en/item/81068

- Ars Technica, 2026-09-30 20:44 UTC
- Tech
- Original: https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/

> Microsoft warned that hackers are exploiting a critical vulnerability in Zimbra Collaboration Suite to seek email backups and authentication credentials from vulnerable organizations. The flaw allows unauthenticated remote operating-system command execution. Although Synacor issued a patch on July 20, Shadowserver later found 274 compromised instances.
