← Back to blog

Zimbra Flaw Exploited to Deploy Web Shells and Steal Credentials

Attackers are exploiting a critical Zimbra vulnerability to gain remote code execution and harvest authentication data. Organizations using Zimbra Collaboration Suite should patch immediately.

TL;DR

  • Threat actors exploited CVE-2026-73570, an unauthenticated command injection flaw in Zimbra.
  • The vulnerability allows remote code execution and deployment of web shells.
  • Attackers accessed mailbox data and harvested authentication secrets.
  • Microsoft Security Research identified active exploitation in the wild.
  • Organizations must apply patches and audit systems for compromise indicators.

A critical security flaw in Zimbra Collaboration Suite is under active exploitation by threat actors. The vulnerability, tracked as CVE-2026-73570, allows unauthenticated attackers to execute arbitrary commands on affected servers.

According to Microsoft Security Research, adversaries are leveraging this flaw to deploy web shells and gain persistent access to internal systems. Once inside, they are targeting mailbox data and harvesting sensitive authentication credentials.

Organizations running Zimbra instances are advised to take immediate action to mitigate risks associated with this high-severity flaw.

Vulnerability Overview

  • CVE-2026-73570 is an unauthenticated operating system command injection vulnerability.
  • It affects Zimbra Collaboration Suite (ZCS) deployments with SNMP enabled.
  • The flaw carries a CVSS score of 8.9, indicating high severity.
  • Successful exploitation leads to remote code execution without authentication.
  • Patched versions are available from Zimbra to address the issue.

Attack Tactics and Impact

  • Attackers deploy web shells to maintain persistent access post-exploitation.
  • Compromised servers are used to access user mailbox contents.
  • Authentication tokens and credentials are harvested for further attacks.
  • Microsoft Security Research confirmed real-world exploitation campaigns.
  • Indicators of compromise include suspicious files in web-accessible directories.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.