Security researchers have uncovered that cybercriminals began exploiting a serious operating system command injection vulnerability in the Zimbra Collaboration Suite (ZCS) shortly after patches were released but before the vulnerability was publicly disclosed, according to a report by Microsoft.
Details of the Zimbra Vulnerability
Identified as CVE-2026-73570 with a CVSS score of 8.9, this vulnerability arises because ZCS, in versions prior to 10.1.20, inadequately sanitizes untrusted input during SNMP notification processing. This flaw can be exploited if the zimbra-snmp package is installed and SNMP notifications are enabled, allowing attackers to initiate the security flaw through specially crafted SMTP requests.
Successfully exploiting this vulnerability grants unauthorized attackers the ability to execute remote code with the privileges of the Zimbra user. To mitigate the risk, patches addressing CVE-2026-73570 were made available in ZCS version 10.1.20 on July 20, with the vulnerability being publicly disclosed on August 13.
Early Exploitation and Attack Methods
The vulnerability was highlighted as exploited by CERT Polska, who released indicators of compromise (IoCs) on August 17. However, exploitation in the wild commenced between the time of patch release and public disclosure. Microsoft noted that between July 28 and August 7, two unique scanning tools were observed probing the vulnerable injection point.
This reconnaissance activity utilized an execution path later observed during the exploitation phase, intended to verify command execution via lightweight probes without deploying a payload. Following this, attackers were seen installing JSP webshells in publicly accessible application directories, executing content with tools such as wget or curl, initiating background processes, and establishing interactive reverse shells.
Measures for Zimbra Users
According to Microsoft, the attackers further mapped clusters, fingerprinted the environment, and escalated privileges to root using legitimate Zimbra tools. They deployed a secondary persistence mechanism via a systemd service named zimlog.service. The attackers also targeted Zimbra’s centralized service and authentication secrets for credential exfiltration, using the compromised credentials for authenticated LDAP queries to obtain high-value secrets.
To protect themselves, Zimbra Collaboration Suite users are advised to upgrade their systems to version 10.1.20 or later, remove optional packages, disable the vulnerable configuration, restrict SNMP and SMTP access, and thoroughly inspect their environments for any signs of compromise.
Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack
Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
