Threat Actors Weaponize Zimbra Flaw to Deploy Web Shells and Steal Mailbox Data
A critical vulnerability in **Zimbra Collaboration Suite (ZCS)**, tracked as **CVE-2026-73570**, has been actively exploited by threat actors to gain unauthorized access to mail servers. The attacks involve deploying web shells, escalating privileges, and exfiltrating sensitive mailbox and authentication data, as detailed by the **Microsoft Security Research team**.

Threat actors have been observed weaponizing a now-patched security flaw in **Zimbra Collaboration Suite (ZCS)** to deploy web shells and access mailbox data. These findings come from the **Microsoft Security Research team**, highlighting a significant risk to organizations using vulnerable **Zimbra** instances.
### The Vulnerability: CVE-2026-73570
The attack leverages **CVE-2026-73570** (CVSS score: 8.9), an unauthenticated operating system command injection flaw. This vulnerability can lead to remote code execution when **Simple Network Management Protocol (SNMP)** notifications are enabled and the optional `zimbra-snmp` package is installed.
Exploitation of **CVE-2026-73570** can be triggered by a specially crafted SMTP request, targeting exposed **Zimbra** servers without requiring authentication or user interaction. **Zimbra** released a patch for this vulnerability in July 2026 with version 10.1.20.
### Attack Chain and Impact
**Microsoft** reported that successful exploitation led to the deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution. Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer observed.
Organizations across various regions and industries have been affected, although the full attack chain was not observed in every instance. The identity of the threat actors behind these attacks remains unknown.
### Disclosure and Response Timeline
Details of active exploitation of **CVE-2026-73570** were first highlighted by the **Polish Computer Emergency Response Team (CERT Polska)** in August 2026. **CERT Polska** urged users to review `/var/log/zimbra.log` for suspicious **Zimbra** service restarts and to look for newly created files in temporary and **Zimbra** webapps directories.
Later that month, the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** added the flaw to its **Known Exploited Vulnerabilities (KEV)** catalog, mandating federal agencies to apply fixes by August 24, 2026.
**Microsoft's** telemetry data indicates that attack activity occurred between July 20, 2026, when **Zimbra** version 10.1.20 was released, and August 13, 2026, when the flaw was publicly disclosed. Specifically, between July 28 and August 7, 2026, two distinct out-of-band scanning tools were observed probing the injection path to validate command execution.
### Post-Exploitation Activities
Attackers leveraged initial access to run commands as the `zimbra` service account, deploying multiple JSP web shells across Jetty and mailboxd application paths for redundancy. They also downloaded and executed malicious payloads via `wget` or `curl`, and established interactive reverse shells.

**Microsoft** noted that other execution chains used `cron`, `systemd`, or `memfd_create` for recurring or memory-backed execution. In some cases, attackers temporarily enabled write access to public directories to deploy web shells, then restored original permissions to limit visibility.
Subsequent steps undertaken by threat actors included:
* Mapping the **Zimbra** deployment using `zmprov` to identify mailbox and MTA nodes.
* Checking for the **Zimbra SSH identity** to facilitate lateral movement.
* Using a privilege-escalation technique to grant the `zimbra` service account unrestricted, passwordless sudo access by modifying `/etc/pam.d/sudo`.
* Creating a `systemd` service named `zimlog.service` for persistence at system boot.
* Targeting **Zimbra's** centralized service and authentication secrets using `zmlocalconfig -s` to retrieve high-value attributes like `zimbraPreAuthKey`, `zimbraAuthTokenKey`, and `zimbraTwoFactorAuthSecret`.
* Utilizing **Zimbra's** existing SSH identity at `/opt/zimbra/.ssh/zimbra_identity` for lateral movement, transferring JSP web shells and helper scripts via `rsync`.
* Employing an OpenSSL-encrypted reverse shell to attacker-controlled infrastructure for command execution, payload retrieval, and exfiltration.
### Advanced Payloads and Data Exfiltration
In at least one campaign, attackers used a lightweight shell downloader for a **Zimdown2 Go** binary, which then acted as an installer for the **Zimclient2** remote-access agent. **Zimclient2** offers interactive shell access, bidirectional file operations, and SOCKS5 proxying, supporting WebSocket, TLS, and raw TCP transports for resilient remote access and network pivoting.
Evidence identified several persistence mechanisms associated with **Zimclient2**, including `systemd` services, OpenRC, `cron`, shell startup files, SSH authorized keys, and local account creation.
**Zimbra**-specific payloads were also deployed, including a Go-based executable designed to extract **Zimbra** service-account credentials from `/opt/zimbra/conf/localconfig.xml`. These credentials were then used to construct MySQL and LDAP connection strings to the **Zimbra MySQL** instance and export contents from critical database tables such as `mailbox`, `mailbox_metadata`, `mobile_devices`, `out_of_office`, and all tables in the `zimbra.*` namespace.
The implant also collected and staged credential, certificate, LDAP secret, mail-rule, and configuration artifacts, compressing them into a ZIP archive for exfiltration.
On one compromised **Zimbra** server, the actor archived recent mailbox-backup content into `/opt/zimbra/final.tar.gz`. They then downloaded **AzCopy** from `hxxps://aka[.]ms/downloadazcopy-v10-linux` and invoked it with an operator-supplied Azure Blob SAS URL targeting `wsweb03[.]blob[.]core[.]windows[.]net/log/windows.log`. This activity demonstrates mailbox-data collection, local archive staging, and an exfiltration attempt using cloud-storage tooling, though successful transfer was not confirmed.
### Mitigation Recommendations
Organizations are strongly advised to apply the latest **Zimbra** updates immediately. If patching is not feasible, it is recommended to uninstall the `zimbra-snmp` package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts only. Additional safeguards include rotating **Zimbra** authentication secrets and scanning servers for redundant web shell persistence.