Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zimbra Flaw Exploited for Web Shell Deployment

Zimbra Flaw Exploited for Web Shell Deployment

Posted on September 30, 2026 By CWS

Recent findings by the Microsoft Security Research team reveal that threat actors have exploited a now-patched vulnerability in the Zimbra Collaboration Suite (ZCS) to deploy web shells and access sensitive mailbox data. This exploitation targets the CVE-2026-73570 vulnerability, a critical unauthenticated operating system command injection flaw with a CVSS score of 8.9 that allows remote code execution when SNMP notifications are enabled and the optional zimbra-snmp package is installed.

Details of the Security Breach

The exploitation of CVE-2026-73570 can be initiated via a specially crafted SMTP request, affecting exposed Zimbra servers without requiring authentication. Zimbra addressed this vulnerability in July 2026 with the release of version 10.1.20. According to Microsoft, successful exploitation has led to the deployment of JSP web shells and reverse shells, privilege escalation, and the use of persistent remote-access tools, with threat actors accessing email and harvesting authentication information.

Global Impact and Discovery

Microsoft observed this attack affecting organizations across multiple regions and industries. Although not all affected hosts exhibited every stage of the attack, the precise identity of the threat actors remains unknown. Initial reports of the active exploitation came from the Polish Computer Emergency Response Team (CERT Polska) in August 2026, which urged users to check for suspicious activity, such as service restarts and file creations in specific directories.

Furthermore, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply necessary patches by August 24, 2026. Microsoft documented attack activities occurring between July 20 and August 13, 2026, with initial reconnaissance using out-of-band scanning tools.

Attack Techniques and Mitigation

Attackers utilized the initial access to execute commands as the “zimbra” service account, deploying multiple JSP web shells and downloading malicious payloads. They maintained persistence through cron jobs, systemd services, and memory-backed execution techniques. In some instances, attackers briefly enabled write access to public directories to deploy web shells, minimizing detection by reverting permissions afterward.

To mitigate these threats, organizations are strongly advised to apply the latest security updates. If patching is not feasible, it’s recommended to remove the zimbra-snmp package, disable SNMP notifications, and limit SNMP and SMTP access to trusted hosts. Additional measures include rotating authentication secrets and scanning for redundant web shell persistence.

Conclusion and Security Recommendations

The exploitation of the Zimbra flaw underscores the importance of timely vulnerability patching and proactive security measures. Organizations must remain vigilant and implement recommended safeguards to prevent unauthorized access and data breaches. By staying informed and responsive, businesses can protect their systems against evolving cybersecurity threats.

The Hacker News Tags:authentication breach, CERT Polska, CISA, CVE-2026-73570, cyber attack, cybersecurity threat, mailbox data, Microsoft security, network security, remote code execution, SNMP, vulnerability patching, web shell, Zimbra security

Post navigation

Previous Post: Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics
Next Post: Cloudflare Advances Quantum-Safe Internet Security

Related Posts

Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks The Hacker News
Cybersecurity Updates: Microsoft, Zerion Breaches, and More Cybersecurity Updates: Microsoft, Zerion Breaches, and More The Hacker News
OpenAI Discloses Six AI Model Failures and New Framework OpenAI Discloses Six AI Model Failures and New Framework The Hacker News
Cisco Highlights Exploitation of Catalyst SD-WAN Vulnerabilities Cisco Highlights Exploitation of Catalyst SD-WAN Vulnerabilities The Hacker News
Why More Security Leaders Are Selecting AEV Why More Security Leaders Are Selecting AEV The Hacker News
New Advanced Linux VoidLink Malware Targets Cloud and container Environments New Advanced Linux VoidLink Malware Targets Cloud and container Environments The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Chrome Update Fixes 32 Security Vulnerabilities
  • Phishing Campaigns Use MSP360 for Hidden Access
  • Cloudflare Advances Quantum-Safe Internet Security
  • Zimbra Flaw Exploited for Web Shell Deployment
  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Chrome Update Fixes 32 Security Vulnerabilities
  • Phishing Campaigns Use MSP360 for Hidden Access
  • Cloudflare Advances Quantum-Safe Internet Security
  • Zimbra Flaw Exploited for Web Shell Deployment
  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark