thehackernews.com 30 Sept 2026, 16:46 UTC

Attackers Exploit Zimbra Flaw to Steal Mail and Maintain Access

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

THREAT actors have weaponised a now-patched Zimbra Collaboration Suite (ZCS) flaw to deploy web shells, harvest mailbox data and credentials, and establish persistent access. The vulnerability, CVE-2026-73570, is an unauthenticated OS command-injection flaw that can trigger remote code execution when SNMP notifications are enabled and the optional zimbra-snmp package is installed. Exploitation can be triggered by a specially crafted SMTP request against exposed Zimbra servers, without user interaction. Zimbra patched this in July 2026 with version 10.1.20.

Microsoft’s Security Research team reports that after successful exploitation, attackers deployed JSP and memory-backed web shells, escalated privileges, and established remote-access tooling. They observed access to email and collection of authentication and mailbox data, with archive creation and subsequent transfer activity.

In campaigns seen across multiple regions and industries, attackers mapped the deployment, leveraged the zimbra identity for lateral movement, and used a zimbra sudo privilege escalation method to obtain passwordless access. They deployed multiple persistence mechanisms (systemd services, cron, memfd_create, OpenRC) and exfiltrated data via OpenSSH-enabled paths and cloud-storage tooling, including AzCopy with a SAS URL.

CISA later added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies apply fixes by 24 August 2026. Practical responses include patching to 10.1.20, uninstalling zimbra-snmp, disabling SNMP notifications, restricting SNMP and SMTP access to trusted hosts, rotating Zimbra authentication secrets, and scanning for web shell persistence.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline