Attackers Exploit Critical Zimbra Flaw in Attempt to Steal Emails and Credentials

Attackers Exploit Critical Zimbra Flaw in Attempt to Steal Emails and Credentials

Follow on Google Join Facebook Group WhatsApp Channel

Threat actors have been actively exploiting a critical vulnerability in the Zimbra Collaboration Suite (ZCS) in an effort to acquire email backups and authentication credentials from vulnerable organizations, according to a security warning issued by Microsoft.

TL;DR: Key Points

  • The Flaw: Tracked as CVE-2026-73570, the security bug allows unauthenticated remote attackers to execute arbitrary operating system commands with zimbra service account privileges.
  • Attack Vector: Exploitation is triggered via a specially crafted SMTP message targeting SNMP notification processing, applicable when the optional zimbra-snmp package is installed and active.
  • Observed Activity: Microsoft detected scanning campaigns, deployment of JSP web shells and reverse shells, privilege escalation, and commands issued to back up mailboxes and collect credentials.
  • Current Scale: Internet scans by the Shadowserver Foundation revealed 274 compromised Zimbra servers, out of roughly 10,000 active instances currently tracked.
  • Remediation: Administrators should upgrade their deployments to Zimbra Collaboration Suite version 10.1.20 or later.

Understanding CVE-2026-73570: How the Command Injection Flaw Works

The vulnerability, tracked as CVE-2026-73570, is a critical unauthenticated command injection flaw within the Zimbra Collaboration Suite. It gives remote attackers the ability to execute underlying operating system commands without having to log in or supply valid user credentials.

According to technical findings shared by Microsoft, the flaw resides in how Zimbra processes system notifications. An attacker can submit a crafted SMTP request that delivers untrusted input directly into the SNMP notification handling routine. If that input is insufficiently sanitized, embedded shell commands execute under the security privileges of the local zimbra service account.

However, researchers emphasized that the vulnerability is conditional: it can be exploited only when the optional zimbra-snmp package is present on the server and SNMP notifications have been enabled by the administrator.

Attacker Methodology: Probing, Web Shells, and Mailbox Targeting

Microsoft reported that between July 28 and August 7, its threat intelligence systems identified two distinct scanning tools probing internet-facing networks for vulnerable Zimbra servers.

During the early phase of the operation, attackers validated that their exploit payloads functioned as intended without compromising the host systems. They achieved this by issuing HTTP requests and dispatching DNS, ICMP, and out-of-band identity checks to domains hosted on public services. These non-destructive probes confirmed that arbitrary commands were executing on target servers.

Following validation, the attackers shifted to deploying malicious payloads. Microsoft documented post-exploitation activities involving both automated payload delivery and manual, hands-on-keyboard operations:

  • Web Shell and Backdoor Deployment: Attackers deployed JSP web shells, reverse shells, and persistent remote-access tools, alongside executing code directly in memory.
  • Privilege Escalation: Intruders elevated permissions within the host operating system to solidify their hold.
  • Targeting Email Archives: Threat actors accessed user inboxes, created email archives, and engaged in subsequent transfer operations.
  • Credential Harvesting: Using the installed web shells, attackers issued commands specifically to harvest authentication credentials and mailbox backups.

Microsoft noted that affected organizations were located in multiple geographic regions and spanned diverse industries, confirming that the campaign was broad rather than restricted to a single country or sector.

Confirmed Evidence Versus Key Uncertainties

In analyzing the incidents, security researchers drew a clear line between confirmed observations and unverified outcomes:

  • Data Exfiltration Status: While Microsoft confirmed that attackers executed commands to assemble email archives and gather authentication credentials, the company stated it had no means to verify whether the threat actors successfully exfiltrated that data from the victim networks.
  • Attribution: Microsoft did not attribute the activity to a specific group or nationality, leaving it undetermined whether the perpetrators were state-backed espionage groups or financially motivated cybercriminals.

Timeline and Global Infection Footprint

Zimbra maintainer Synacor released a patch addressing the security issue on July 20. However, the company did not publicly disclose the vulnerability for more than three weeks following the patch release.

Telemetry released by the non-profit Shadowserver Foundation documented significant fallout from the delay. Internet-wide scanning conducted by Shadowserver identified 274 separate instances of the Zimbra Collaboration Suite that had been compromised. The organization also reported that the total number of exposed Zimbra servers fluctuated from approximately 19,000 in the week immediately following the July patch down to around 12,000 in subsequent weeks. Currently, Shadowserver tracks approximately 10,000 active instances online.

Recommended Defense and Mitigation Actions

Organizations running the Zimbra Collaboration Suite should take immediate action to protect their email environments:

  1. Apply Updates: Verify that all instances are updated to Zimbra Collaboration Suite version 10.1.20 or later, which resolves the flaw.
  2. Review SNMP Configurations: Check if the optional zimbra-snmp package is installed and disable unnecessary SNMP notifications on internet-facing systems.
  3. Audit for Indicators of Compromise: Scan servers for unauthorized JSP files, unexpected reverse shells, abnormal memory-resident processes, and unexplained archive generation commands.
  4. Consult Additional Hardening Guides: Follow supplementary system lockdown recommendations published by Microsoft and security researchers.

Frequently Asked Questions

What is CVE-2026-73570?

CVE-2026-73570 is a critical unauthenticated command injection vulnerability in the Zimbra Collaboration Suite that enables remote attackers to run operating system commands with zimbra service account privileges by sending a specially crafted SMTP message.

What conditions must be met for a server to be vulnerable?

A server running Zimbra Collaboration Suite is vulnerable only if the optional zimbra-snmp package is installed and SNMP notifications are actively enabled.

How many Zimbra instances have been compromised?

According to scans conducted by the Shadowserver Foundation, 274 separate instances of the Zimbra Collaboration Suite have been identified as compromised.

Did the attackers successfully steal corporate email data?

Microsoft observed attackers deploying web shells and issuing commands to create mailbox backups and collect credentials. However, Microsoft stated it had no means to verify whether the attackers succeeded in exfiltrating that information from victim systems.

Which software version fixes CVE-2026-73570?

Administrators should ensure their installations are updated to Zimbra Collaboration Suite version 10.1.20 or later to protect against this vulnerability.

Sources & Further Reading

Post a Comment

0 Comments