www.microsoft.com 30 Sept 2026, 14:00 UTC

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Steal Mail

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

MICROSOFT Threat Intelligence has tracked exploitation of CVE-2026-73570, an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. A crafted SMTP request can reach SNMP notification processing and inject shell commands, executing with the privileges of the zimbra service account when the optional zimbra-snmp package is installed and SNMP notifications are enabled.

Zimbra CE 10.1.20 (released 20 July 2026) contains the remediation, and CVE-2026-73570 was publicly disclosed on 13 August 2026; Microsoft telemetry showed activity targeting the same injection path in the interim.

The campaign observed by Microsoft included rapid, multi-stage exploitation on internet-facing Zimbra servers, with attackers deploying JSP web shells, establishing reverse shells, and pursuing persistence and credential access. Techniques included privilege escalation via PAM/sudo manipulation, systemd service persistence (zimlog[.]service), and other artefacts designed to endure across reboots and to move laterally within Zimbra clusters.

The attackers also conducted data collection from Zimbra’s configuration and mail stores, and in at least one instance attempted exfiltration using AzCopy to Azure Blob storage. In most cases, actions combined automated payloads with hands-on keyboard operations, and activity spanned multiple regions and industries.

Mitigation guidance emphasises patching to 10.1.20 or later, or uninstalling zimbra-snmp and restricting SNMP and SMTP access to trusted hosts. Additional steps include rotating Zimbra secrets, reviewing persistence mechanisms, and enabling Defender for Endpoint protections on Linux servers.

Attackers’ reverse-shell activity on internet-facing mail servers should be treated as priority incidents, and monitoring should look for the exact SNMP injection signature and related web-shell persistence across Zimbra components.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline