A High-Severity Zimbra Vulnerability Was Exploited Before Public Disclosure, Leaving Users Exposed to Remote Code Execution Attacks
In a disturbing example of how quickly cyber threats can be exploited in the wild, hackers began targeting a high-severity vulnerability in the popular email collaboration suite Zimbra Collaboration Suite (ZCS) just days after patches were rolled out. According to Microsoft’s report, the attackers successfully exploited CVE-2026-73570 before it was publicly disclosed on August 13, leaving users vulnerable to remote code execution attacks.
The vulnerability exists due to a flaw in the way untrusted input is sanitized during SNMP notification processing in ZCS versions prior to 10.1.20. If the zimbra-snmp package has been installed and SNMP notifications have enabled, an attacker could trigger the security defect via specially crafted SMTP requests, allowing them to execute arbitrary commands on the affected system with the privileges of the Zimbra user.
Microsoft reports that they observed two distinct out-of-band scanning tools probing the vulnerable injection point between July 28 and August 7. The reconnaissance activity used an execution path that was later seen during exploitation, and was meant to validate command execution via lightweight out-of-band probes without delivering a payload. This was just the beginning of the attackers’ campaign.
As part of their observed follow-up exploitation activity, the attackers deployed JSP webshells to publicly accessible application directories, executed content through wget or curl, launched background processes, and established interactive reverse shells. They also mapped clusters, fingerprinted the environment, checked for the Zimbra SSH identity, escalated privileges to root using legitimate Zimbra tools, and deployed a secondary persistence mechanism using a systemd service named zimlog.service.
The hackers targeted Zimbra’s centralized service and authentication secrets for credential exfiltration, using the login material for authenticated LDAP queries that allowed them to retrieve high-value secrets. They also used Zimbra’s existing SSH identity to access other nodes in the cluster, used HTTP and HTTPS callbacks to validate command execution, and deployed a full remote-access agent providing interactive shell access, bidirectional file operations, and SOCKS5 proxying.
ZCS users are advised to update their instances to version 10.1.20 or later, uninstall the optional package, disable the vulnerable configuration, restrict SNMP and SMTP access, and check their environments for potential compromise. This highlights the importance of staying up-to-date with the latest security patches and monitoring systems for suspicious activity.
In this case, the attackers’ ability to exploit a vulnerability before public disclosure is a stark reminder that the window between patching and disclosure can be perilously short. It’s crucial for organizations to prioritize timely patching, implement robust security controls, and stay vigilant in detecting potential threats.
Source: SecurityWeek — 2026-10-01