
Attackers Exploit Patched Zimbra Flaw to Deploy Web Shells and Steal Mail Secrets
Microsoft says attackers exploited CVE-2026-73570 in Zimbra Collaboration Suite to plant JSP web shells, escalate privileges and harvest authentication and mailbox data.
Threat actors exploited a now-patched Zimbra Collaboration Suite (ZCS) flaw to plant web shells and reach mailbox data, Microsoft's Security Research team reported on September 30, 2026.
The flaw, tracked as CVE-2026-73570 and rated 8.9 on the CVSS scale, is an unauthenticated command injection that can lead to remote code execution when SNMP notifications are enabled and the optional zimbra-snmp package is installed. It can be triggered by a specially crafted email sent to an exposed Zimbra server.
Patched in July, exploited before disclosure
Zimbra fixed the bug in July 2026 with version 10.1.20, and Microsoft said the activity fell between that release on July 20 and the public disclosure on August 13. From July 28 to August 7, two out-of-band scanning tools probed the injection path to confirm command execution without a payload.
Active exploitation was first flagged by the Polish CERT (CERT Polska) in August 2026. That month CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by August 24.
From web shells to mailbox exfiltration
After gaining a foothold, the attackers ran commands as the "zimbra" service account and deployed multiple JSP web shells across Jetty and mailboxd paths. They fetched and ran payloads with wget or curl, opened reverse shells, and used cron or systemd for persistence.
Microsoft described a deeper chain too: mapping the deployment with zmprov, abusing the Zimbra SSH identity, and granting the service account passwordless sudo by editing /etc/pam.d/sudo. Instead of cracking individual mailboxes, the operators ran "zmlocalconfig -s" to pull centralized authentication secrets, then used LDAP queries to retrieve attributes such as zimbraPreAuthKey.
Zimdown2 and Zimclient2
In at least one campaign the operators installed a Go binary called Zimdown2, which deployed the Zimclient2 remote-access agent offering an interactive shell, file transfers and SOCKS5 proxying.
A separate Go executable pulled Zimbra service-account credentials from localconfig.xml and exported database tables such as mailbox and mobile_devices. On one server the actor archived mailbox backups and used AzCopy with an Azure Blob URL to push data to the cloud; Microsoft said the evidence does not confirm the transfer completed.
What organizations should do
Organizations should apply the Zimbra updates immediately. Where patching is not an option, Microsoft recommends uninstalling the zimbra-snmp package, disabling SNMP notifications and restricting SNMP and SMTP access to trusted hosts only.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.