Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Zimbra Flaw Before Official Disclosure

Hackers Exploit Zimbra Flaw Before Official Disclosure

Posted on October 1, 2026 By CWS

Security researchers have uncovered that cybercriminals began exploiting a serious operating system command injection vulnerability in the Zimbra Collaboration Suite (ZCS) shortly after patches were released but before the vulnerability was publicly disclosed, according to a report by Microsoft.

Details of the Zimbra Vulnerability

Identified as CVE-2026-73570 with a CVSS score of 8.9, this vulnerability arises because ZCS, in versions prior to 10.1.20, inadequately sanitizes untrusted input during SNMP notification processing. This flaw can be exploited if the zimbra-snmp package is installed and SNMP notifications are enabled, allowing attackers to initiate the security flaw through specially crafted SMTP requests.

Successfully exploiting this vulnerability grants unauthorized attackers the ability to execute remote code with the privileges of the Zimbra user. To mitigate the risk, patches addressing CVE-2026-73570 were made available in ZCS version 10.1.20 on July 20, with the vulnerability being publicly disclosed on August 13.

Early Exploitation and Attack Methods

The vulnerability was highlighted as exploited by CERT Polska, who released indicators of compromise (IoCs) on August 17. However, exploitation in the wild commenced between the time of patch release and public disclosure. Microsoft noted that between July 28 and August 7, two unique scanning tools were observed probing the vulnerable injection point.

This reconnaissance activity utilized an execution path later observed during the exploitation phase, intended to verify command execution via lightweight probes without deploying a payload. Following this, attackers were seen installing JSP webshells in publicly accessible application directories, executing content with tools such as wget or curl, initiating background processes, and establishing interactive reverse shells.

Measures for Zimbra Users

According to Microsoft, the attackers further mapped clusters, fingerprinted the environment, and escalated privileges to root using legitimate Zimbra tools. They deployed a secondary persistence mechanism via a systemd service named zimlog.service. The attackers also targeted Zimbra’s centralized service and authentication secrets for credential exfiltration, using the compromised credentials for authenticated LDAP queries to obtain high-value secrets.

To protect themselves, Zimbra Collaboration Suite users are advised to upgrade their systems to version 10.1.20 or later, remove optional packages, disable the vulnerable configuration, restrict SNMP and SMTP access, and thoroughly inspect their environments for any signs of compromise.

Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack

Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Security Week News Tags:CERT Polska, CVE-2026-73570, cyber attack, Cybersecurity, Hacking, Information Security, Microsoft, remote code execution, security patch, SMTP, SNMP, system security, Vulnerability, Webshells, Zimbra

Post navigation

Previous Post: Modernizing Software Supply Chains in Finance
Next Post: Zimbra Mail Server Vulnerability Exploited by Hackers

Related Posts

Brightspeed Investigating Cyberattack – SecurityWeek Brightspeed Investigating Cyberattack – SecurityWeek Security Week News
Vulnerabilities Expose Helmholz Industrial Routers to Hacking Vulnerabilities Expose Helmholz Industrial Routers to Hacking Security Week News
Arch Linux Project Responding to Week-Long DDoS Attack Arch Linux Project Responding to Week-Long DDoS Attack Security Week News
Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics Security Week News
In Other News: X Fined €120 Million, Array Flaw Exploited, New Iranian Backdoor In Other News: X Fined €120 Million, Array Flaw Exploited, New Iranian Backdoor Security Week News
Aikido Security Raises  Million at  Billion Valuation Aikido Security Raises $60 Million at $1 Billion Valuation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WordPress Malware Resurfaces with Self-Healing Backdoor
  • AI Impacts Cyber Attack Speed, Fundamentals Remain Key
  • CISA Identifies Critical Flaw in Cisco SD-WAN Manager
  • Zimbra Mail Server Vulnerability Exploited by Hackers
  • Hackers Exploit Zimbra Flaw Before Official Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WordPress Malware Resurfaces with Self-Healing Backdoor
  • AI Impacts Cyber Attack Speed, Fundamentals Remain Key
  • CISA Identifies Critical Flaw in Cisco SD-WAN Manager
  • Zimbra Mail Server Vulnerability Exploited by Hackers
  • Hackers Exploit Zimbra Flaw Before Official Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark