INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest
| 2026-09-30 14:58 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Between July 20, 2026 and August 13, 2026, attackers exploited CVE-2026-73570, an unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite's SNMP notification path. Multiple organizations across different regions were affected through both automated payload delivery and hands-on-keyboard operations targeting internet-facing Zimbra mail servers. The attack works by delivering JSP webshells and reverse shells without requiring authentication, achieving privilege escalation through PAM configuration abuse and establishing persistent access via systemd services. Post-exploitation activity included cluster-wide lateral movement using Zimbra SSH keys, collection of authentication secrets and mailbox data, and attempted exfiltration using cloud-storage tools. The current status is that the vulnerability has been patched, but attackers have already exploited it to deploy web shells and harvest authentication secrets in multiple organizations worldwide.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-73570 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ws•••••.net
me•••••.com
ps•••••.com
re•••••.com
fi•••••.tar
fi•••••.gz
93eac8••••••••••••••••••••••••••••••••••
1e03cb••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
bf28f3••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
65a757••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
dee5af••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
22ef85••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
3.209.•••.•••
192.255.•••.•••
117.107.•••.•••
45.32.•••.•••
f214d3••••••••••••••••••••••••••
66555a••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-73570CVE-2026-73570
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
July 2026
Zimbra released version 10.1.20 in July 2026 to patch the unauthenticated command injection vulnerability, CVE-2026-73570.
Click on any entity below to view its context and source!
infrastructure
10.1.20
The vulnerability was patched by Zimbra in July 2026 with the release of version 10.1.20.
July 20, 2026
Threat actors exploited a vulnerability in internet-facing mail servers (CVE-2026-73570) between July 20, 2026 and August 13, 2026.
between July 20, 2026
Threat actors exploited a vulnerability in Zimbra version 10.1.20 between July 20, and August 13, 2026.
Click on any entity below to view its context and source!
infrastructure
10.1.20
Based on telemetry data, the attack activity documented by Microsoft was identified "during the interval" between July 20, 2026, when Zimbra version 10.1.20 was released, and August 13, 2026, when the flaw was publicly disclosed.
August 2026
Threat actors used the vulnerability CVE-2026-73570 to target internet-facing Zimbra mail servers.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-73570
Details of active exploitation of CVE-2026-73570 were
first highlighted
by the Polish Computer Emergency Response Team (CERT Polska) in August 2026, with the agency urging users to review the "/var/log/zimbra.log" file for suspicious Zimbra service restarts, and look for files created in temporary and Zimbra "webapps" directories.
observable
zimbra.log
Details of active exploitation of CVE-2026-73570 were
first highlighted
by the Polish Computer Emergency Response Team (CERT Polska) in August 2026, with the agency urging users to review the "/var/log/zimbra.log" file for suspicious Zimbra service restarts, and look for files created in temporary and Zimbra "webapps" directories.
attribution
CVE-2026
Details of active exploitation of CVE-2026-73570 were
first highlighted
by the Polish Computer Emergency Response Team (CERT Polska) in August 2026, with the agency urging users to review the "/var/log/zimbra.log" file for suspicious Zimbra service restarts, and look for files created in temporary and Zimbra "webapps" directories.
attribution
the Polish Computer Emergency Response Team
Details of active exploitation of CVE-2026-73570 were
first highlighted
by the Polish Computer Emergency Response Team (CERT Polska) in August 2026, with the agency urging users to review the "/var/log/zimbra.log" file for suspicious Zimbra service restarts, and look for files created in temporary and Zimbra "webapps" directories.
August 7, 2026
Threat actors exploited a vulnerability in the Apache James mail server (CVE-2026-73570) to execute arbitrary commands on internet-facing servers.
August 13, 2026
Threat actors exploited the unauthenticated command injection vulnerability in Zimbra version 10.1.20 between July 20, and August 13, 2026.
Click on any entity below to view its context and source!
infrastructure
10.1.20
Based on telemetry data, the attack activity documented by Microsoft was identified "during the interval" between July 20, 2026, when Zimbra version 10.1.20 was released, and August 13, 2026, when the flaw was publicly disclosed.
August 24, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2026-73570 vulnerability to its Known Exploited Vulnerabilities catalog, mandating that federal agencies apply fixes by August 24, 2026.
Click on any entity below to view its context and source!
attribution
Known Exploited
Later that month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies apply the fixes by August 24, 2026.
tactic
T1588.006 - Vulnerabilities
Later that month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies apply the fixes by August 24, 2026.
attribution
KEV
Later that month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies apply the fixes by August 24, 2026.
between July 28 and August 7, 2026
Threat actors used out-of-band scanning tools to probe the injection path on internet-facing mail servers between July 28 and August 7, 2026.
2026/09/30
Threat actors exploited the unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite's SNMP notification path, tracked as CVE-2026-73570.
Click on any entity below to view its context and source!
organisation
CVE-2026
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance.
organisation
Unauthenticated
The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog .
organisation
Microsoft Security Blog
The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog .
organisation
CVE-2026-73570
Microsoft Threat Intelligence identified active exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite's SNMP notification path.
organisation
Simple Network Management Protocol (
The attack exploits
CVE-2026-73570
(CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol (SNMP) notifications are enabled and the optional zimbra-snmp package is installed.
organisation
SMTP
Exploitation of CVE-2026-73570 can be triggered by a specially crafted SMTP request (i.e., email against exposed Zimbra servers without requiring authentication or user interaction.
organisation
JSP
Attackers delivered JSP webshells and reverse shells without requiring authentication, achieving privilege escalation through PAM configuration abuse and establishing persistent access via systemd services.
"Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution," the tech giant
said
.
organisation
PAM
Attackers delivered JSP webshells and reverse shells without requiring authentication, achieving privilege escalation through PAM configuration abuse and establishing persistent access via systemd services.
organisation
SSH
Utilize Zimbra's existing SSH identity at "/opt/zimbra/.ssh/zimbra_identity" to enable lateral movement across other trusted nodes in the cluster.
infrastructure
Linux
"The actor then downloaded AzCopy from hxxps://aka[.]ms/downloadazcopy-v10-linux and invoked it with an operator-supplied Azure Blob SAS URL targeting wsweb03[.]blob[.]core[.]windows[.]net/log/windows.log."
"This activity shows mailbox-data collection, local archive staging, and an exfiltration attempt using cloud-storage tooling; available evidence does not confirm that the transfer completed…
infrastructure
Windows
"The actor then downloaded AzCopy from hxxps://aka[.]ms/downloadazcopy-v10-linux and invoked it with an operator-supplied Azure Blob SAS URL targeting wsweb03[.]blob[.]core[.]windows[.]net/log/windows.log."
"This activity shows mailbox-data collection, local archive staging, and an exfiltration attempt using cloud-storage tooling; available evidence does not confirm that the transfer completed…
organisation
the Zimbra MySQL
This includes a Go-based executable that attempts to extract Zimbra service-account credentials from "/opt/zimbra/conf/localconfig.xml," and use these values to construct MySQL and LDAP connection strings to the Zimbra MySQL instance and export the contents of the following database tables -
mailbox
mailbox_metadata
mobile_devices
out_of_office
All tables in the zimbra.
organisation
Zimbra Collaboration Suite
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.
organisation
ZCS
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.
organisation
the Microsoft Security Research
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.
organisation
Microsoft
"
Microsoft said it observed affected organizations in more than one region and industry, although not every host exhibited every stage of the attack chain.
organisation
MTA
"
Some of the subsequent steps undertaken by the threat actor are listed below -
Map the Zimbra deployment using zmprov to identify mailbox and MTA nodes for environment discovery.
organisation
the Zimbra SSH
Check for the presence of the Zimbra SSH identity to likely facilitate movement between Zimbra hosts.
organisation
WebSocket
"It supported WebSocket, TLS, and raw TCP transports, providing resilient remote access and potential network pivoting through compromised Zimbra servers," Microsoft said.
organisation
TLS
"It supported WebSocket, TLS, and raw TCP transports, providing resilient remote access and potential network pivoting through compromised Zimbra servers," Microsoft said.
organisation
TCP
"It supported WebSocket, TLS, and raw TCP transports, providing resilient remote access and potential network pivoting through compromised Zimbra servers," Microsoft said.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
"The actor then downloaded AzCopy from hxxps://aka[.]ms/downloadazcopy-v10-linux and invoked it with an operator-supplied Azure Blob SAS URL targeting wsweb03[.]blob[.]core[.]windows[.]net/log/windows.log."
"This activity shows mailbox-data collection, local archive staging, and an exfiltration attempt using cloud-storage tooling; available evidence does not confirm that the transfer completed…
Metrics
infrastructure
Windows
Affected Product
"The actor then downloaded AzCopy from hxxps://aka[.]ms/downloadazcopy-v10-linux and invoked it with an operator-supplied Azure Blob SAS URL targeting wsweb03[.]blob[.]core[.]windows[.]net/log/windows.log."
"This activity shows mailbox-data collection, local archive staging, and an exfiltration attempt using cloud-storage tooling; available evidence does not confirm that the transfer completed…
Metrics
infrastructure
10.1.20
Software Version
The vulnerability was patched by Zimbra in July 2026 with the release of version 10.1.20.
Based on telemetry data, the attack activity documented by Microsoft was identified "during the interval" between July 20, 2026, when Zimbra version 10.1.20 was released, and August 13, 2026, when the flaw was publicly disclosed.
Intelligence Sources
The Hacker News
2026-09-30
AlienVault OTX
2026-09-30
AlienVault OTX
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:19
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
CVE-2026
entity
8x
timeline
Temporal Reference
July 20, 2026
date
6x
attribution
Attributing Entity
Microsoft Threat Intelligence
authority
4x
tactic
Cyber Operation Type
Privilege Escalation
tactic
3x
target region
Target Country
United States
country
2x
infrastructure
Affected Product
Linux
software
Contextual Telemetry
Context Block
4 METRICS
vulnerability
Exploited CVE
CVE-2026-73570
cve
general metric
Score
9
score
infrastructure
Software Version
10.1.20
version
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.