Remember when the scariest thing in your inbox was a badly photoshopped bank logo asking you to confirm your password? That was the era when email security felt like a personal responsibility. Don’t click the weird link, don’t open the surprise invoice, and you were mostly fine.
That version of the threat is almost quaint now. The latest Zimbra story is a reminder that sometimes nobody has to click anything at all.
What actually happened
Attackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570. Zimbra is email and calendar software that organizations run on their own servers, which means it quietly holds the correspondence of a lot of companies, universities, and government offices.
The flaw lets an attacker remotely run operating system commands without authentication. In plain terms, that means no password, no stolen login, no tricking an employee. Send the right malicious input at a vulnerable server and the server does what you tell it.
Specifically, the vulnerability can be triggered by a crafted SMTP request when SNMP notifications are enabled and the zimbra-snmp package is installed. SMTP is the protocol email servers use to pass messages around. SNMP is a monitoring protocol, the kind of plumbing that exists so administrators can keep an eye on system health. Two boring, unglamorous components, combined into an unlocked door.
Microsoft’s Security Research team found that threat actors used the flaw to access mailbox data. Attackers also deployed web shells and harvested authentication secrets. Zimbra maintainer Synacor issued a patch on July 20, but the vulnerability was exploited before it was disclosed.
Three terms worth translating
- Web shell — a small piece of code an attacker leaves behind on a server that gives them an ongoing control panel. Patching the original hole later does not remove it. Think of it as a spare key taped under the doormat.
- Authentication secrets — the tokens, keys, and credentials that software uses to prove who it is. Humans have passwords. Machines have secrets, and they hand them to each other constantly.
- Exploited before disclosure — attackers knew about the weakness before defenders did. The fix existed before the public explanation did, which is a strange and uncomfortable gap.
Why I’m writing about this on an AI site
I spend most of my time explaining AI agents, so you might reasonably wonder why an email server bug belongs here. The answer is that your mailbox has quietly become one of the most AI-connected things you own.
Agents read email. They summarize threads, draft replies, pull out action items, schedule meetings, file receipts, and route support tickets. To do any of that, they need access. That access is granted with exactly the kind of authentication secrets attackers were collecting here.
So think about what a stolen mailbox means in a world where agents are wired into it:
- Context becomes ammunition. Email archives contain org charts, vendor relationships, invoice formats, and the specific way your CFO signs off. An attacker with that material can write a convincing request without needing a single typo-ridden template.
- Tokens open more than one door. Machine credentials often reach beyond email into calendars, file storage, and connected tools. One compromised server can become a map of everything it talks to.
- Agents trust their inputs. An AI assistant reading a mailbox generally treats the contents as legitimate information to act on. If an attacker can place messages in that mailbox, they are not just reading your mail, they are potentially feeding instructions to software that acts on your behalf.
That last point is the one I’d underline for anyone building agent workflows right now. We tend to secure the AI tool itself and assume the data source feeding it is clean. Email was never a clean data source. It is the most publicly addressable inbox in your organization.
What a non-technical reader can reasonably do
You are probably not the person patching a Zimbra server. Still, a few things are in your control.
Ask whoever runs your email whether your systems are patched and whether anyone checked for leftover web shells. Patching closes the hole, but it does not evict a guest who already moved in. Ask what credentials your AI tools hold and whether those were rotated. If secrets were harvested, replacing them matters more than almost anything else.
And keep a human in the loop for anything consequential. An agent that drafts a wire transfer request is useful. An agent that sends one unreviewed is a liability, especially when its source of truth might have been sitting wide open for weeks.
The new tools are genuinely good. The old infrastructure underneath them is still where the trouble starts.
🕒 Published: