Hackers Exploit Critical Zimbra Vulnerability to Steal Email and Authentication Data
Hackers are actively exploiting a critical vulnerability in Zimbra Collaboration Suite to target vulnerable organizations and obtain email backups, authentication credentials, and mailbox data, Microsoft warned.
The vulnerability, tracked as CVE-2026-73570, allows unauthenticated attackers to remotely execute operating system commands on affected Zimbra servers.
What is CVE-2026-73570?
CVE-2026-73570 enables uncredentialed remote attackers to execute operating system commands through a crafted email targeting the Zimbra Collaboration Suite SNMP notification path. Exploitation requires the optional zimbra-snmp package to be installed and SNMP notifications to be enabled.
Zimbra maintainer Synacor issued a patch on July 20 but did not disclose the vulnerability for more than three weeks.
Attackers scanned the internet for vulnerable Zimbra servers
Microsoft reported that it detected two scanning tools searching for vulnerable endpoints on the internet between July 28 and August 7.
Attackers initially tested whether the exploit worked by sending HTTP requests, DNS and ICMP checks, and out-of-band identification requests to a domain hosted on a public service. These probes allowed them to confirm that commands had executed on vulnerable servers without immediately compromising them.
Shadowserver Foundation, a security organization focused on internet-wide threat monitoring, reported last week that its scans identified 274 compromised Zimbra Collaboration Suite instances.
The number of internet-facing Zimbra servers observed by Shadowserver fell from approximately 19,000 during the week after the patch was released to about 12,000 the following week. Shadowserver is currently tracking approximately 10,000 instances.
What attackers do after exploiting Zimbra
After confirming that command injection was possible, attackers began using the vulnerability to install malicious payloads and establish persistent access.
After successful exploitation, observed activities include JSP web shell and reverse shell deployment, privilege escalation, persistent remote access tools, and memory back execution. Threat actors were also observed accessing emails to collect authentication and mailbox data, as well as archive creation and subsequent forwarding activity. This activity included both automatic delivery of payloads and keyboard operations on compromised email servers. Microsoft observed affected organizations across multiple regions and industries. Based on the environments studied, exploitation was not limited to a single sector or geographical area.
The observed activity includes web shells, reverse shells, privilege escalation, persistent remote-access tools, and memory-based execution. Attackers also accessed email accounts to collect authentication information and mailbox data, created archives, and forwarded the stolen material.
Why organizations using Zimbra should act
Because CVE-2026-73570 can be exploited remotely without authentication, internet-facing Zimbra servers may be targeted before administrators detect suspicious activity. Organizations should apply the available Zimbra patch and investigate affected systems for unauthorized commands, web shells, reverse shells, persistent tools, and unusual email access or forwarding activity.
Source: arstechnica.com


