Critical Vulnerability: Attackers Exploit Zimbra ZCS for Remote Code Execution
Threat actors are actively exploiting CVE-2026-73570, a critical unauthenticated operating system command injection flaw in Zimbra Collaboration Suite (ZCS), to achieve remote code execution (RCE), deploy web shells, and harvest sensitive authentication and mailbox data. The vulnerability, which carries a CVSS score of 8.9, affects ZCS instances where Simple Network Management Protocol (SNMP) notifications are enabled and the optional zimbra-snmp package is installed. Successful exploitation can be triggered by a specially crafted SMTP request against exposed Zimbra servers, requiring no authentication or user interaction, according to findings from the Microsoft Security Research team.
This flaw allows attackers to establish persistent access, escalate privileges, and exfiltrate valuable information from compromised mail servers. Organizations across multiple regions and industries have been observed as targets, emphasizing the widespread risk posed by this vulnerability.
Technical Details of CVE-2026-73570 Exploitation
The vulnerability, identified as an unauthenticated OS command injection, enables threat actors to execute arbitrary commands on the underlying operating system. The exploit chain begins with a crafted SMTP request, leveraging the zimbra-snmp package to gain initial access. Following successful exploitation, the observed activities include:
- Initial Access & Persistence: Attackers deploy JSP web shells across various Jetty and mailboxd application paths for redundancy. They also establish interactive reverse shells and utilize various techniques for persistence, including
cronjobs,systemdservices,memfd_createfor memory-backed execution, and temporarily modifying directory permissions to deploy web shells before restoring original settings. - Payload Deployment: In some campaigns, a lightweight shell downloader for a
Zimdown2Go binary has been used to install theZimclient2remote-access agent. This agent provides interactive shell access, bidirectional file operations, and SOCKS5 proxying, offering resilient remote access and potential network pivoting capabilities through compromised Zimbra servers.Zimclient2maintains persistence through mechanisms likesystemdservices, OpenRC,cronentries, shell startup files, SSH authorized keys, and local account creation. - Credential Harvesting: Attackers deploy Zimbra-specific Go-based executables designed to extract service-account credentials from
/opt/zimbra/conf/localconfig.xml. These credentials are then used to construct MySQL and LDAP connection strings, allowing the attackers to export sensitive database table contents. - Data Exfiltration: The threat actors collect and stage various artifacts, including credentials, certificates, LDAP secrets, mail rules, and configuration files. These are compressed into ZIP archives for subsequent transfer. Notably, one observed instance involved an attacker archiving recent mailbox backup content and attempting exfiltration using AzCopy, downloaded from
hxxps://aka[.]ms/downloadazcopy-v10-linux, targeting an Azure Blob Storage SAS URL.
Detecting and Mitigating CVE-2026-73570 Exploitation
Zimbra released a patch for this vulnerability in July 2026 with the introduction of version 10.1.20. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies apply the fixes promptly. Organizations using Zimbra Collaboration Suite must prioritize patching to prevent active exploitation.
Immediate Actions:
- Patching: The primary and most effective mitigation is to immediately update all Zimbra Collaboration Suite instances to version 10.1.20 or newer. This provides the most comprehensive protection against this actively exploited flaw. If you are researching Zimbra Collaboration Suite 10.1.20 patch guidance, ensure your update process adheres to vendor recommendations.
- Alternative Mitigations (if patching is not feasible):
- Uninstall the
zimbra-snmppackage. - Disable SNMP notifications.
- Restrict SNMP and SMTP access to trusted hosts only.
- Uninstall the
- Post-Compromise Remediation & Detection:
- Rotate all Zimbra authentication secrets immediately.
- Scan your Zimbra servers for redundant web shell persistence. Review the
/var/log/zimbra.logfile for suspicious Zimbra service restarts. Look for newly created or modified files in temporary directories (/tmp) and Zimbrawebappsdirectories, as highlighted by CERT Polska. - Monitor network traffic for unusual outbound connections, especially to cloud storage services or command-and-control infrastructure.
Failing to address this vulnerability promptly leaves Zimbra instances highly susceptible to compromise, leading to data breaches and persistent unauthorized access.
Related: CVE-2026-53413: Zoom Zero-Click RCE – Patch Now, Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder