Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Attackers exploit Zimbra flaw CVE-2026-73570 to deploy web shells and harvest authentication secrets.
Summary
Threat actors are actively exploiting a critical vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite to deploy web shells, escalate privileges, and steal authentication secrets. The unauthenticated OS command injection flaw allows for remote code execution, leading to the deployment of persistent access tools and the exfiltration of mailbox data. Microsoft Security Research and CERT Polska have highlighted the exploitation, with CISA adding it to its Known Exploited Vulnerabilities catalog.
Full text
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Ravie LakshmananSep 30, 2026Vulnerability / Email Security Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol (SNMP) notifications are enabled and the optional zimbra-snmp package is installed. Exploitation of CVE-2026-73570 can be triggered by a specially crafted SMTP request (i.e., email against exposed Zimbra servers without requiring authentication or user interaction. The vulnerability was patched by Zimbra in July 2026 with the release of version 10.1.20. "Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution," the tech giant said. "Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed." Microsoft said it observed affected organizations in more than one region and industry, although not every host exhibited every stage of the attack chain. It's currently not known who is behind the attacks. Details of active exploitation of CVE-2026-73570 were first highlighted by the Polish Computer Emergency Response Team (CERT Polska) in August 2026, with the agency urging users to review the "/var/log/zimbra.log" file for suspicious Zimbra service restarts, and look for files created in temporary and Zimbra "webapps" directories. Later that month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies apply the fixes by August 24, 2026. Based on telemetry data, the attack activity documented by Microsoft was identified "during the interval" between July 20, 2026, when Zimbra version 10.1.20 was released, and August 13, 2026, when the flaw was publicly disclosed. Specifically, between July 28 and August 7, 2026, two distinct out-of-band scanning tools were found probing the injection path to validate command execution without delivering a follow-on payload. The attackers then abused this initial access pathway to run commands as the "zimbra" service account and deploy multiple JSP web shells across Jetty and mailboxd application paths for redundancy, as well as download and execute malicious payloads directly through wget or curl, and establish interactive reverse shells. "Other execution chains used cron, systemd, or memfd_create to maintain recurring or memory-backed execution," Microsoft said. "In some cases, attackers temporarily enabled write access to a public directory to deploy the web shell and then restored the directory permissions, limiting the visibility of the change during basic permission checks." Some of the subsequent steps undertaken by the threat actor are listed below - Map the Zimbra deployment using zmprov to identify mailbox and MTA nodes for environment discovery. Check for the presence of the Zimbra SSH identity to likely facilitate movement between Zimbra hosts. Use a privilege-escalation technique that grants the "zimbra" service account unrestricted and passwordless sudo access by modifying the "/etc/pam.d/sudo" configuration file. Create a systemd service named "zimlog.service" for a second persistence mechanism that establishes execution at system boot. Target Zimbra's centralized service and authentication secrets by using the "zmlocalconfig -s" command on the server rather than going after individual mailbox passwords. The recovered credentials are then used for authenticated LDAP queries to retrieve high-value attributes, such as zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret. Utilize Zimbra's existing SSH identity at "/opt/zimbra/.ssh/zimbra_identity" to enable lateral movement across other trusted nodes in the cluster. Rsync is used to transfer JSP web shells and other helper scripts between nodes. Employ an OpenSSL-encrypted reverse shell to attacker-controlled infrastructure to conduct command execution, payload retrieval, and exfiltration of command output. In at least one campaign, the attackers have been found to use a lightweight shell downloader for a Zimdown2 Go binary that then acts as an installer for the Zimclient2 remote-access agent. Zimclient2 offers interactive shell access, bidirectional file operations, and SOCKS5 proxying. "It supported WebSocket, TLS, and raw TCP transports, providing resilient remote access and potential network pivoting through compromised Zimbra servers," Microsoft said. "Evidence identified several persistence mechanisms associated with the payload, including systemd services, OpenRC, cron, shell startup files, SSH authorized keys, and local account creation." Also associated with the activity is the deployment of Zimbra-specific payloads. This includes a Go-based executable that attempts to extract Zimbra service-account credentials from "/opt/zimbra/conf/localconfig.xml," and use these values to construct MySQL and LDAP connection strings to the Zimbra MySQL instance and export the contents of the following database tables - mailbox mailbox_metadata mobile_devices out_of_office All tables in the zimbra.* namespace The implant also collects and stages credential, certificate, LDAP secret, mail-rule, and configuration artifacts. The harvested files are compressed into a ZIP archive for subsequent transfer to a remote endpoint. "On one compromised Zimbra server, the actor archived recent mailbox-backup content into /opt/zimbra/final.tar.gz," Microsoft said. "The actor then downloaded AzCopy from hxxps://aka[.]ms/downloadazcopy-v10-linux and invoked it with an operator-supplied Azure Blob SAS URL targeting wsweb03[.]blob[.]core[.]windows[.]net/log/windows.log." "This activity shows mailbox-data collection, local archive staging, and an exfiltration attempt using cloud-storage tooling; available evidence does not confirm that the transfer completed successfully." To counter the threat, organizations are advised to apply the updates immediately. If patching is not an option, it's recommended to uninstall the zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts only. Other safeguards include rotating Zimbra authentication secrets, scanning the server for redundant web shell persistence. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE email security, Malware, Vulnerability ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyH
Indicators of Compromise
- cve — CVE-2026-73570