Vulnerabilities

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.

Zimbra vulnerability exploited

Hackers started exploiting a high-severity OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) shortly after patches were rolled out, before public disclosure, Microsoft reports.

Tracked as CVE-2026-73570 (CVSS score of 8.9), the flaw exists because, in ZCS before 10.1.20, untrusted input during SNMP notification processing is improperly sanitized.

Thus, if the zimbra-snmp package has been installed and SNMP notifications have been enabled, an attacker could trigger the security defect via specially crafted SMTP requests.

Successful exploitation of the bug allows unauthenticated attackers to achieve remote code execution with the privileges of the Zimbra user.

Patches for CVE-2026-73570 were rolled out on July 20 in ZCS version 10.1.20, and the vulnerability was publicly disclosed on August 13.

Poland’s CERT Polska flagged the security defect as exploited and released indicators of compromise (IoCs) on August 17, but in-the-wild exploitation started between patching and public disclosure.

Advertisement. Scroll to continue reading.

“Between July 28 and August 7, after a fix became available on July 20 but before public disclosure on August 13, Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point,” Microsoft says.

The reconnaissance activity used an execution path that was later seen during exploitation, and was meant to validate command execution via lightweight out-of-band probes, without delivering a payload.

As part of the observed follow-up exploitation activity, the attackers deployed JSP webshells to publicly accessible application directories, executed content through wget or curl, launched background processes, and established interactive reverse shells.

“Multiple JSP webshells were deployed across Jetty and mailboxd application paths, including additional copies on peer mailbox nodes. This provided alternative access paths across different Zimbra configurations and reduced reliance on a single webshell,” Microsoft notes.

The attackers then mapped clusters, fingerprinted the environment, checked for the Zimbra SSH identity, escalated privileges to root using legitimate Zimbra tools, and deployed a secondary persistence mechanism using a systemd service named zimlog.service.

According to Microsoft, the hackers targeted Zimbra’s centralized service and authentication secrets for credential exfiltration, and used the login material for authenticated LDAP queries that allowed them to retrieve high-value secrets.

They also used Zimbra’s existing SSH identity to access other nodes in the cluster, used HTTP and HTTPS callbacks to validate command execution, and deployed “a full remote-access agent providing interactive shell access, bidirectional file operations, and SOCKS5 proxying”.

Zimbra Collaboration Suite users are advised to update their instances to version 10.1.20 or later, uninstall the optional package, disable the vulnerable configuration, restrict SNMP and SMTP access, and check their environments for potential compromise.

Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack

Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Related Content

Malware & Threats

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

Vulnerabilities

CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system.

Artificial Intelligence

The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.

Vulnerabilities

The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges.

Artificial Intelligence

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

Vulnerabilities

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.

Vulnerabilities

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

Vulnerabilities

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version