Ethical Hacking News
A critical vulnerability in Zimbra Collaboration Suite has left many organizations vulnerable to attacks. The vulnerability, identified as CVE-2026-73570, has a CVSS score of 8.9, making it a high-severity exploit. In this article, we will explore the details of the vulnerability, how it was exploited, and the potential risks it poses to email security. Organizations are advised to apply the updates immediately and take proactive measures to secure their email infrastructure.
Recent vulnerability discovered in Zimbra Collaboration Suite (ZCS) with high-severity exploit (CVSS score 8.9) Attack exploits unauthenticated operating system command injection flaw leading to remote code execution Threat actors accessed mailbox data, deployed JSP web shells, and collected authentication and email data without authentication or user interaction Attack chain involves environment discovery, privilege escalation, and lateral movement across trusted nodes Recommendations include applying patches, disabling SNMP notifications, and restricting access to trusted hosts only Organizations must take proactive measures to secure their email infrastructure and monitor for suspicious activity
The world of cybersecurity is ever-evolving, with new vulnerabilities being discovered and exploited every day. Recently, a significant vulnerability was discovered in Zimbra Collaboration Suite (ZCS) that has left many organizations on high alert. In this article, we will delve into the details of the vulnerability, how it was exploited, and the potential risks it poses to email security.
According to recent reports, threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data. The vulnerability, identified as CVE-2026-73570, has a CVSS score of 8.9, making it a high-severity exploit. The vulnerability was patched by Zimbra in July 2026 with the release of version 10.1.20.
The attack exploits an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol (SNMP) notifications are enabled and the optional zimbra-snmp package is installed. Exploitation of CVE-2026-73570 can be triggered by a specially crafted SMTP request, which allows attackers to access mailbox data without requiring authentication or user interaction.
Following successful exploitation, observed activity included the deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution. Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed.
Microsoft observed affected organizations in more than one region and industry, although not every host exhibited every stage of the attack chain. It's currently not known who is behind the attacks.
To understand the attack chain, let's break down the steps taken by the threat actors. The attackers first mapped the Zimbra deployment using zmprov to identify mailbox and MTA nodes for environment discovery. They then checked for the presence of the Zimbra SSH identity to likely facilitate movement between Zimbra hosts.
Next, they used a privilege-escalation technique that granted the "zimbra" service account unrestricted and passwordless sudo access by modifying the "/etc/pam.d/sudo" configuration file. They created a systemd service named "zimlog.service" for a second persistence mechanism that established execution at system boot.
The threat actors then targeted Zimbra's centralized service and authentication secrets by using the "zmlocalconfig -s" command on the server rather than going after individual mailbox passwords. They recovered credentials and used them for authenticated LDAP queries to retrieve high-value attributes, such as zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret.
Utilizing Zimbra's existing SSH identity at "/opt/zimbra/.ssh/zimbra_identity" enabled lateral movement across other trusted nodes in the cluster. They used Rsync to transfer JSP web shells and other helper scripts between nodes.
Employing an OpenSSL-encrypted reverse shell allowed attackers to conduct command execution, payload retrieval, and exfiltration of command output. In at least one campaign, the attackers used a lightweight shell downloader for a Zimdown2 Go binary that then acted as an installer for the Zimclient2 remote-access agent.
The Zimclient2 remote-access agent offered interactive shell access, bidirectional file operations, and SOCKS5 proxying. It supported WebSocket, TLS, and raw TCP transports, providing resilient remote access and potential network pivoting through compromised Zimbra servers.
In conclusion, the recent vulnerability in Zimbra Collaboration Suite (ZCS) poses a significant threat to email security. Organizations are advised to apply the updates immediately or uninstall the zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts only. Rotating Zimbra authentication secrets and scanning servers for redundant web shell persistence are also recommended.
To counter this threat, organizations must take proactive measures to secure their email infrastructure. This includes applying patches, monitoring for suspicious activity, and implementing robust security measures to prevent unauthorized access to mailbox data.
Related Information:
https://www.ethicalhackingnews.com/articles/Exploiting-the-Zimbra-Vulnerability-A-Threat-to-Email-Security-ehn.shtml
https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html
https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html
https://nvd.nist.gov/vuln/detail/CVE-2026-73570
https://www.cvedetails.com/cve/CVE-2026-73570/
Published: Wed Sep 30 13:08:28 2026 by llama3.2 3B Q4_K_M