黑客一直在利用 Zimbra Collaboration Suite 中的严重漏洞,试图获取易受攻击组织的电子邮件备份和身份验证凭据,微软已发出警告。
Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned.
该漏洞编号为 CVE-2026-73570,可使攻击者在无需身份验证的情况下远程发出操作系统命令。Zimbra 维护方 Synacor 于 7 月 20 日发布了补丁,但在此之后三周多才披露该漏洞。专注于网络安全领域的 Shadowserver Foundation 上周表示,其扫描发现 274 个不同的 Zimbra Collaboration Suite 实例已遭入侵。运行该软件的服务器数量从补丁发布后一周的 19,000 台降至之后几周的大约 12,000 台。目前,Shadowserver 正在追踪约 10,000 个实例。
The vulnerability, tracked as CVE-2026-73570, lets attackers remotely issue operating system commands without authentication. Zimbra maintainer Synacor issued a patch on July 20, but didn’t disclose the vulnerability for more than three weeks after that. The security-focused Shadowserver Foundation said last week that its scans found that 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks following that. Currently, Shadowserver is tracking about 10,000 instances.
微软周三表示,从 7 月 28 日至 8 月 7 日,该公司检测到两种不同的扫描工具在互联网上探测存在漏洞的端点。攻击者首先通过向公共服务托管的域名发送 HTTP 请求,以及 DNS、ICMP 和带外身份检查,来验证其漏洞利用代码是否有效。借助这些探测,攻击者得以确认漏洞利用代码已在易受攻击的服务器上成功执行命令,而实际上并未入侵这些服务器。最终,攻击者开始利用命令注入能力安装恶意载荷。微软写道:
From July 28 to August 7, Microsoft said Wednesday, the company detected two distinct scanning tools probing the Internet for vulnerable endpoints. The attackers first validated their exploit worked by sending HTTP, requests and DNS, ICMP, and out-of-band identity checks to domains hosted on public services. The probes allowed the attackers to confirm the exploit successfully executed commands on vulnerable servers without actually compromising them. Eventually, the attackers began using their command injection capability to install malicious payloads. Microsoft wrote: