securityonline.info 30 Sept 2026, 15:33 UTC

Unpatched Zimbra Servers Exposed to Shells and Credential Theft

Unpatched Zimbra Servers Exposed to Shells and Credential Theft
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

MICROSOFT Threat Intelligence has tracked attacks exploiting Zimbra CVE-2026-73570, an unauthenticated command-injection flaw in the SNMP notification path, that can give attackers a shell on exposed, unpatched servers. The article notes that exploitation requires the optional zimbra-snmp package to be installed and SNMP notifications enabled.

In the observed campaigns, attackers moved from initial footholds to web shells, privilege escalation, and credential theft, with some attempts to exfiltrate mailbox backups to cloud storage. Shadowserver counted 8,200+ unpatched instances as of late August, while 274 servers had already been compromised.

The attack chain begins with a malicious SMTP request that injects shell commands into Zimbra’s SNMP alerts; the commands are later executed via a health monitor, running with the zimbra service account. After establishing a presence, the intruders deployed JSP web shells on public Zimbra folders and on peer nodes, then exploited a writable Zimbra log file to pivot to root by injecting a hook into sudoers via a Zimbra helper.

They also planted a fake systemd service for persistence and, in some cases, deployed a Go-based tool to harvest master secrets, including LDAP, MySQL, and Postfix credentials and signing keys. The operators then attempted to spread laterally across cluster nodes using shared SSH keys and, in one campaign, used a Go remote-access agent. Evidence suggests attackers also sought to archive mailbox backups and upload them with AzCopy, though Microsoft notes that evidence does not confirm completion of the transfer.

Defenders are urged to patch to Zimbra 10.1.20 (released 20 July 2026) or later, remove or disable the zimbra-snmp package if SNMP is unnecessary, and hunt for rogue JSP files, new password-free sudo rules, and unfamiliar systemd units, cron jobs, or SSH keys. ROTATE service passwords and regenerate auth and pre-auth keys if compromise is suspected, and alert on AzCopy or similar cloud- uploading tools. Patching alone may not remove an active intruder, so treat exposed, unpatched servers as potentially compromised until proven otherwise.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline