Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Microsoft Security Research team has discovered that threat actors are exploiting a patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data.

The flaw in question is CVE-2026-73570, an unauthenticated operating system command injection vulnerability with a CVSS score of 8.9. This flaw can result in remote code execution when SNMP notifications are enabled, and the zimbra-snmp package is installed.

Attackers can exploit CVE-2026-73570 by sending a specially crafted SMTP request to exposed Zimbra servers without requiring authentication. Zimbra patched this vulnerability in July 2026 with the release of version 10.1.20.

After successful exploitation, attackers deployed JSP web shells and reverse shells, escalated privileges, established persistent remote access, and executed commands in memory. They also accessed emails, collected authentication and mailbox data, created archives, and transferred data.

Microsoft observed affected organizations in various regions and industries. However, the identity of the attackers behind these exploits remains unknown.

The Polish Computer Emergency Response Team (CERT Polska) first highlighted active exploitation of CVE-2026-73570 in August 2026. They recommended users to check for suspicious activities in the “/var/log/zimbra.log” file.

Subsequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply fixes by August 24, 2026.

Microsoft’s telemetry data revealed attack activities between July 20, 2026, and August 13, 2026. During this period, attackers used out-of-band scanning tools to probe the injection path, deploy web shells, and establish reverse shells.

The attackers employed various tactics, such as leveraging cron, systemd, or memfd_create for recurring executions, enabling write access to public directories, and creating persistence mechanisms for continued access.

Furthermore, the attackers mapped Zimbra deployments, escalated privileges, established persistence mechanisms, and retrieved high-value attributes using recovered credentials.

One campaign involved the deployment of a lightweight shell downloader for a Zimdown2 Go binary, which acted as an installer for the Zimclient2 remote-access agent. Zimclient2 provided interactive shell access, file operations, and proxying capabilities.

Additionally, the attackers deployed Zimbra-specific payloads to extract credentials, export database tables, collect artifacts, and attempt exfiltration using cloud-storage tools.

Organizations are advised to apply updates promptly, uninstall the zimbra-snmp package, disable SNMP notifications, restrict SNMP and SMTP access, rotate authentication secrets, and scan for redundant web shell persistence to mitigate the threat.