Back to Feed
VulnerabilitiesOct 1, 2026

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Zimbra vulnerability CVE-2026-73570 exploited in the wild before public disclosure.

Summary

Hackers exploited a critical OS command injection vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite before it was publicly disclosed. Exploitation occurred between the patching date and public disclosure, allowing attackers to achieve remote code execution and deploy webshells. Microsoft observed scanning tools probing the vulnerability, followed by exploitation that led to credential exfiltration and the deployment of a remote access agent.

Full text

Hackers started exploiting a high-severity OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) shortly after patches were rolled out, before public disclosure, Microsoft reports. Tracked as CVE-2026-73570 (CVSS score of 8.9), the flaw exists because, in ZCS before 10.1.20, untrusted input during SNMP notification processing is improperly sanitized. Thus, if the zimbra-snmp package has been installed and SNMP notifications have been enabled, an attacker could trigger the security defect via specially crafted SMTP requests. Successful exploitation of the bug allows unauthenticated attackers to achieve remote code execution with the privileges of the Zimbra user. Patches for CVE-2026-73570 were rolled out on July 20 in ZCS version 10.1.20, and the vulnerability was publicly disclosed on August 13. Poland’s CERT Polska flagged the security defect as exploited and released indicators of compromise (IoCs) on August 17, but in-the-wild exploitation started between patching and public disclosure.Advertisement. Scroll to continue reading. “Between July 28 and August 7, after a fix became available on July 20 but before public disclosure on August 13, Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point,” Microsoft says. The reconnaissance activity used an execution path that was later seen during exploitation, and was meant to validate command execution via lightweight out-of-band probes, without delivering a payload. As part of the observed follow-up exploitation activity, the attackers deployed JSP webshells to publicly accessible application directories, executed content through wget or curl, launched background processes, and established interactive reverse shells. “Multiple JSP webshells were deployed across Jetty and mailboxd application paths, including additional copies on peer mailbox nodes. This provided alternative access paths across different Zimbra configurations and reduced reliance on a single webshell,” Microsoft notes. The attackers then mapped clusters, fingerprinted the environment, checked for the Zimbra SSH identity, escalated privileges to root using legitimate Zimbra tools, and deployed a secondary persistence mechanism using a systemd service named zimlog.service. According to Microsoft, the hackers targeted Zimbra’s centralized service and authentication secrets for credential exfiltration, and used the login material for authenticated LDAP queries that allowed them to retrieve high-value secrets. They also used Zimbra’s existing SSH identity to access other nodes in the cluster, used HTTP and HTTPS callbacks to validate command execution, and deployed “a full remote-access agent providing interactive shell access, bidirectional file operations, and SOCKS5 proxying”. Zimbra Collaboration Suite users are advised to update their instances to version 10.1.20 or later, uninstall the optional package, disable the vulnerable configuration, restrict SNMP and SMTP access, and check their environments for potential compromise. Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire WatchGuard Patches Critical Fireware OS Code Injection VulnerabilityChrome, Firefox Updates Patch Over 100 VulnerabilitiesRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come ForwardReco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksDutch Police Arrest Convicted Hacker in ShinyHunters InvestigationDaemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft Latest News AI Has Changed Attack Speed, Not Security FundamentalsKevin Mandia’s Armadin Raises $255 Million at $2.5 Billion ValuationTreasury Blacklists Most-Wanted ATM Malware Developer and His NetworkZammad Zero-Days Exploited in AI-Powered DIVD Hack500,000 Active Credentials Left Exposed on GitHubCisco Patches Exploited Catalyst SD-WAN Zero-Day VulnerabilityGoogle Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersFTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-73570

Entities

Zimbra Collaboration Suite (product)Zimbra (vendor)Microsoft (vendor)