INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest

| 2026-09-30 14:58 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Between July 20, 2026 and August 13, 2026, attackers exploited CVE-2026-73570, an unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite's SNMP notification path. Multiple organizations across different regions were affected through both automated payload delivery and hands-on-keyboard operations targeting internet-facing Zimbra mail servers. The attack works by delivering JSP webshells and reverse shells without requiring authentication, achieving privilege escalation through PAM configuration abuse and establishing persistent access via systemd services. Post-exploitation activity included cluster-wide lateral movement using Zimbra SSH keys, collection of authentication secrets and mailbox data, and attempted exfiltration using cloud-storage tools. The current status is that the vulnerability has been patched, but attackers have already exploited it to deploy web shells and harvest authentication secrets in multiple organizations worldwide.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-73570 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ws•••••.net
me•••••.com
ps•••••.com
re•••••.com
fi•••••.tar
fi•••••.gz
93eac8••••••••••••••••••••••••••••••••••
1e03cb••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
bf28f3••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
65a757••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
dee5af••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
22ef85••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
3.209.•••.•••
192.255.•••.•••
117.107.•••.•••
45.32.•••.•••
f214d3••••••••••••••••••••••••••
66555a••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-73570CVE-2026-73570
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎July 2026
Zimbra released version 10.1.20 in July 2026 to patch the unauthenticated command injection vulnerability, CVE-2026-73570.
infrastructure 10.1.20
‎July 20, 2026
Threat actors exploited a vulnerability in internet-facing mail servers (CVE-2026-73570) between July 20, 2026 and August 13, 2026.
‎between July 20, 2026
Threat actors exploited a vulnerability in Zimbra version 10.1.20 between July 20, and August 13, 2026.
infrastructure 10.1.20
‎August 2026
Threat actors used the vulnerability CVE-2026-73570 to target internet-facing Zimbra mail servers.
vulnerability CVE-2026-73570
observable zimbra.log
attribution CVE-2026
attribution the Polish Computer Emergency Response Team
‎August 7, 2026
Threat actors exploited a vulnerability in the Apache James mail server (CVE-2026-73570) to execute arbitrary commands on internet-facing servers.
‎August 13, 2026
Threat actors exploited the unauthenticated command injection vulnerability in Zimbra version 10.1.20 between July 20, and August 13, 2026.
infrastructure 10.1.20
‎August 24, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2026-73570 vulnerability to its Known Exploited Vulnerabilities catalog, mandating that federal agencies apply fixes by August 24, 2026.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎between July 28 and August 7, 2026
Threat actors used out-of-band scanning tools to probe the injection path on internet-facing mail servers between July 28 and August 7, 2026.
‎2026/09/30
Threat actors exploited the unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite's SNMP notification path, tracked as CVE-2026-73570.
organisation CVE-2026
organisation Unauthenticated
organisation Microsoft Security Blog
organisation CVE-2026-73570
organisation Simple Network Management Protocol (
organisation SMTP
organisation JSP
organisation PAM
organisation SSH
infrastructure Linux
infrastructure Windows
organisation the Zimbra MySQL
organisation Zimbra Collaboration Suite
organisation ZCS
organisation the Microsoft Security Research
organisation Microsoft
organisation MTA
organisation the Zimbra SSH
organisation WebSocket
organisation TLS
organisation TCP
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎10.1.20
Software Version