Zimbra Vulnerability Exploited Before Disclosure: Cybersecurity Threat Revealed

www.news4hackers.com-zimbra-vulnerability-exploited-before-disclosure-cybersecurity-threat-revealed-zimbra-vulnerability-exploited-before-disclosure-cybersecurity-threat-revealed

A critical OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) was actively exploited by threat actors prior to its official disclosure, according to Microsoft.

Vulnerability Details

The flaw, tracked as CVE-2026-73570 with a CVSS score of 8.9, arises from insufficient input validation during SNMP notification processing in ZCS versions prior to 10.1.20. This allows unauthenticated attackers to execute arbitrary commands with Zimbra user privileges if the zimbra-snmp package is installed and SNMP notifications are enabled.

CVE-2026-73570 and CVSS Score

The vulnerability can be triggered through specially crafted SMTP requests. Patches for CVE-2026-73570 were released on July 20 as part of ZCS version 10.1.20, but the flaw was publicly disclosed on August 13.

Exploitation Timeline

Poland’s CERT Polska identified the vulnerability as being exploited in the wild and shared indicators of compromise (IoCs) on August 17. However, Microsoft detected in-the-wild exploitation activities between July 28 and August 7, following the patch release but before the public announcement.

Exploitation Methods

During this period, two distinct out-of-band scanning tools were observed probing the vulnerable injection point. These tools used a method later employed during exploitation, focusing on validating command execution through lightweight, non-payload-bearing probes.

Webshell Deployment

Subsequent exploitation efforts involved deploying JSP webshells to publicly accessible application directories. Attackers utilized tools like wget or curl to execute content, initiated background processes, and established interactive reverse shells.

Cluster Environment Mapping

Attackers mapped cluster environments, identified Zimbra SSH identities, and escalated privileges to root using legitimate Zimbra tools. A secondary persistence mechanism was implemented via a systemd service named zimlog.service.

Impact and Tactics

Threat actors targeted Zimbra’s centralized authentication services to exfiltrate credentials, leveraging stolen login details for authenticated LDAP queries to extract sensitive secrets. They also used Zimbra’s SSH identity to access other cluster nodes, validated command execution through HTTP and HTTPS callbacks, and deployed a full remote-access agent offering interactive shell access, bidirectional file operations, and SOCKS5 proxying.

According to Microsoft: “A critical OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) was actively exploited by threat actors prior to its official disclosure.”

Recommendations

Zimbra Collaboration Suite users are urged to update to version 10.1.20 or later, uninstall the optional zimbra-snmp package, disable vulnerable configurations, restrict SNMP and SMTP access, and conduct thorough environment checks for signs of compromise.

Proactive Measures

The incident underscores the urgency of timely patching and proactive monitoring to mitigate risks associated with zero-day vulnerabilities. Security teams are advised to review logs for anomalous activity, validate system configurations, and implement network segmentation to limit potential attack surfaces.

Conclusion

The exploitation of CVE-2026-73570 highlights the critical need for organizations to prioritize patch management and continuous security assessments. Delayed responses to vulnerabilities can leave systems exposed to sophisticated attacks, emphasizing the importance of immediate action and vigilance.



About Author

en_USEnglish