www.securityweek.com 1 Oct 2026, 12:55 UTC

Attackers Exploited Zimbra Flaw Before Public Disclosure

Attackers Exploited Zimbra Flaw Before Public Disclosure
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

SECURITYWEEK reports that attackers began exploiting a high-severity OS command injection in Zimbra Collaboration Suite (ZCS) shortly after patches were released, and before public disclosure. The flaw, CVE-2026-73570 (CVSS 8.9), affects ZCS pre-10.1.20, where untrusted input during SNMP notification processing is not properly sanitised.

If the zimbra-snmp package is installed and SNMP notifications are enabled, an attacker could trigger remote code execution via specially crafted SMTP requests, gaining unauthenticated access with the privileges of the Zimbra user. Patches were delivered in ZCS 10.1.20 on 20 July, with public disclosure on 13 August; Poland’s CERT Polska later flagged exploitation and released IoCs on 17 August, noting in-the-wild activity occurred in the gap between patching and disclosure.

Microsoft notes that between 28 July and 7 August, after the fix, out-of-band scanning tools probed the injection point, using an execution path later seen in exploitation. Follow-up activity included deploying JSP webshells to Jetty and mailboxd paths, retrieving content with wget or curl, and establishing reverse shells.

Attackers mapped clusters, fingerprinted environments, checked for Zimbra SSH identity, and escalated to root with legitimate Zimbra tools, adding a systemd service named zimlog[.]service for persistence. They targeted the central service and authentication secrets for credential exfiltration, used LDAP queries to retrieve high-value secrets, and leveraged SSH identities to access peer nodes, ultimately deploying a remote-access agent with interactive shell and SOCKS5 proxying.

Zimbra users should upgrade to 10.1.20 or newer, uninstall the optional package, disable vulnerable configurations, restrict SNMP and SMTP access, and review for indicators of compromise.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline