VMTech
Discuss a project →

Exploited Zimbra flaw enables mailbox access and secret theft

Exploited Zimbra flaw enables mailbox access and secret theft

Attackers have exploited CVE-2026-73570, an unauthenticated operating-system command injection vulnerability in Zimbra Collaboration Suite, to deploy web shells, access mailbox data and collect authentication secrets. The flaw has a CVSS score of 8.9 and was fixed in Zimbra version 10.1.20, released in July 2026.

Microsoft Security Research observed activity affecting organizations in more than one region and industry. The attacks occurred during the period from the July 20 release of the fix to the public disclosure on August 13. The identity of the operators remains unknown.

SMTP request can trigger remote code execution

The vulnerable path can be reached through a specially crafted SMTP request without authentication or user interaction. It requires SNMP notifications to be enabled and the optional zimbra-snmp package to be installed on an exposed Zimbra server. CERT Polska highlighted active exploitation in August, and CISA later added the vulnerability to its Known Exploited Vulnerabilities catalog.

Microsoft identified two distinct out-of-band scanning tools probing the injection path between July 28 and August 7. These tools validated command execution without delivering a follow-on payload. Subsequent intrusions ran under the zimbra service account and placed multiple JSP web shells in Jetty and mailboxd application paths, giving attackers redundant access routes.

Persistence and credential collection

Observed activity included reverse shells, payload downloads through wget or curl, privilege escalation and memory-backed execution. Some execution chains used cron, systemd or memfd_create, while attackers in some cases briefly made a public directory writable to place a web shell before restoring its permissions.

The operators modified /etc/pam.d/sudo to give the zimbra account unrestricted passwordless sudo access and created a systemd service called zimlog.service. They also checked for Zimbra's SSH identity at /opt/zimbra/.ssh/zimbra_identity, then used it and rsync to move tools and web shells between trusted cluster nodes.

Rather than target individual mailbox passwords, the attackers used zmlocalconfig -s to obtain centralized service and authentication secrets. The recovered material enabled LDAP queries for high-value attributes including zimbraPreAuthKey, zimbraAuthTokenKey and zimbraTwoFactorAuthSecret. Microsoft also documented Zimdown2, a downloader for the Zimclient2 remote-access agent, which supports interactive shells, bidirectional file operations and SOCKS5 proxying over WebSocket, TLS or raw TCP.

Mailbox data was staged for transfer

A Zimbra-specific Go payload sought credentials in /opt/zimbra/conf/localconfig.xml, constructed MySQL and LDAP connection strings, and exported mailbox-related tables and data in the zimbra namespace. It also staged credential, certificate, LDAP-secret, mail-rule and configuration artifacts in ZIP archives.

On one compromised server, the actor archived recent mailbox-backup content into /opt/zimbra/final.tar.gz and used AzCopy with an operator-supplied Azure Blob SAS URL. Microsoft found evidence of staging and an exfiltration attempt, but could not confirm that the transfer completed.

Organizations should apply version 10.1.20 immediately, rotate Zimbra authentication secrets and investigate for redundant web shells and persistence. Where patching cannot happen at once, removing zimbra-snmp, disabling SNMP notifications, and limiting SNMP and SMTP access to trusted hosts reduce exposure while remediation proceeds.

#zimbra#cybersecurity#vulnerability#emailsecurity
Open analytics
On the site 1 views
min read 4 30.09.2026
Instagram

Exploited Zimbra flaw enables mailbox access and secret theft

Open the post on Instagram ↗