# CVE-2026-73570: Unauthenticated RCE in Zimbra ZCS Exploited

> Threat actors are actively exploiting CVE-2026-73570, an unauthenticated RCE flaw in Zimbra Collaboration Suite, to deploy web shells and exfiltrate sensitive data.

- Published: 2026-10-01T03:05:44.000Z
- Severity: critical
- Category: Vulnerabilities
- Tags: Zimbra, Webshell, Remote Code Execution, Data Exfiltration, CVE-2026-73570
- CVEs: CVE-2026-73570 (CVSS 8.9)
- Author: Runtime Rebel Intel
- Primary source: https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html
- Canonical: https://runtimerebel.com/blog/cve-2026-73570-unauthenticated-rce-in-zimbra-zcs-exploited

## Key points

- Threat actors are actively exploiting a Zimbra RCE flaw to deploy web shells and steal sensitive data.
- Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20 are vulnerable to exploitation.
- Immediately patch Zimbra instances to version 10.1.20 to prevent active exploitation.

## Critical [Vulnerability](/glossary#vulnerability): Attackers [Exploit](/glossary#exploit) Zimbra ZCS for Remote Code Execution

Threat actors are actively exploiting [CVE-2026-73570](/cve/cve-2026-73570), a critical unauthenticated operating system [command injection](/glossary#command-injection) flaw in Zimbra Collaboration Suite (ZCS), to achieve remote code execution ([RCE](/glossary#rce)), deploy web shells, and harvest sensitive authentication and mailbox data. The vulnerability, which carries a [CVSS](/glossary#cvss) score of 8.9, affects ZCS instances where Simple Network Management Protocol (SNMP) notifications are enabled and the optional `zimbra-snmp` package is installed. Successful exploitation can be triggered by a specially crafted SMTP request against exposed Zimbra servers, requiring no authentication or user interaction, according to findings from the [Microsoft Security Research team](https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html).

This flaw allows attackers to establish persistent access, escalate privileges, and exfiltrate valuable information from compromised mail servers. Organizations across multiple regions and industries have been observed as targets, emphasizing the widespread risk posed by this vulnerability.

### Technical Details of [CVE](/glossary#cve)-2026-73570 Exploitation

The vulnerability, identified as an unauthenticated OS command injection, enables threat actors to execute arbitrary commands on the underlying operating system. The [exploit chain](/glossary#exploit-chain) begins with a crafted SMTP request, leveraging the `zimbra-snmp` package to gain [initial access](/glossary#initial-access). Following successful exploitation, the observed activities include:

*   **Initial Access & [Persistence](/glossary#persistence)**: Attackers deploy JSP web shells across various Jetty and mailboxd application paths for redundancy. They also establish interactive reverse shells and utilize various techniques for persistence, including `cron` jobs, `systemd` services, `memfd_create` for memory-backed execution, and temporarily modifying directory permissions to deploy web shells before restoring original settings.
*   **[Payload](/glossary#payload) Deployment**: In some campaigns, a lightweight shell downloader for a `Zimdown2` Go binary has been used to install the `Zimclient2` remote-access agent. This agent provides interactive shell access, bidirectional file operations, and SOCKS5 proxying, offering resilient remote access and potential network pivoting capabilities through compromised Zimbra servers. `Zimclient2` maintains persistence through mechanisms like `systemd` services, OpenRC, `cron` entries, shell startup files, [SSH](/glossary#secure-shell-ssh) authorized keys, and local account creation.
*   **[Credential Harvesting](/glossary#credential-harvesting)**: Attackers deploy Zimbra-specific Go-based executables designed to extract service-account credentials from `/opt/zimbra/conf/localconfig.xml`. These credentials are then used to construct MySQL and LDAP connection strings, allowing the attackers to export sensitive database table contents.
*   **[Data Exfiltration](/glossary#data-exfiltration)**: The threat actors collect and stage various artifacts, including credentials, certificates, LDAP secrets, mail rules, and configuration files. These are compressed into ZIP archives for subsequent transfer. Notably, one observed instance involved an attacker archiving recent mailbox backup content and attempting exfiltration using AzCopy, downloaded from `hxxps://aka[.]ms/downloadazcopy-v10-linux`, targeting an Azure Blob Storage SAS URL.

### Detecting and Mitigating CVE-2026-73570 Exploitation

Zimbra released a [patch](/glossary#patch) for this vulnerability in July 2026 with the introduction of version 10.1.20. The U.S. [Cybersecurity and Infrastructure Security Agency (CISA)](/glossary#cybersecurity-and-infrastructure-security-agency-cisa) has added [CVE-2026-73570](https://nvd.nist.gov/vuln/detail/CVE-2026-73570) to its Known Exploited Vulnerabilities ([KEV](/glossary#kev)) catalog, mandating federal agencies apply the fixes promptly. Organizations using Zimbra Collaboration Suite must prioritize patching to prevent active exploitation.

**Immediate Actions:**

*   **Patching**: The primary and most effective mitigation is to immediately update all Zimbra Collaboration Suite instances to **version 10.1.20** or newer. This provides the most comprehensive protection against this actively exploited flaw. If you are researching Zimbra Collaboration Suite 10.1.20 patch guidance, ensure your update process adheres to vendor recommendations.
*   **Alternative Mitigations (if patching is not feasible):**
    *   Uninstall the `zimbra-snmp` package.
    *   Disable SNMP notifications.
    *   Restrict SNMP and SMTP access to trusted hosts only.
*   **Post-Compromise Remediation & Detection:**
    *   Rotate all Zimbra authentication secrets immediately.
    *   Scan your Zimbra servers for redundant web shell persistence. Review the `/var/log/zimbra.log` file for suspicious Zimbra service restarts. Look for newly created or modified files in temporary directories (`/tmp`) and Zimbra `webapps` directories, as highlighted by CERT Polska.
    *   Monitor network traffic for unusual outbound connections, especially to cloud storage services or command-and-control infrastructure.

Failing to address this vulnerability promptly leaves Zimbra instances highly susceptible to compromise, leading to data breaches and persistent unauthorized access.

**Related:** [CVE-2026-53413: Zoom Zero-Click RCE – Patch Now](/blog/cve-2026-53413-zoom-zero-click-rce-patch-now), [Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder](/blog/pixel-9-zero-click-rce-exploiting-dolby-unified-decoder)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/cve-2026-73570-unauthenticated-rce-in-zimbra-zcs-exploited
