
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.
The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol (SNMP) notifications are enabled and the optional zimbra-snmp package is installed.
Exploitation of CVE-2026-73570 can be triggered by a specially crafted SMTP request (i.e., email against exposed Zimbra servers without requiring authentication or user interaction. The vulnerability was patched by Zimbra in July 2026 with the release of version 10.1.20.
"Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution," the tech giant said. "Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed."
Microsoft said it observed affected organizations in more than one region and industry, although not every host exhibited every stage of the attack chain. It's currently not known who is behind the attacks.
Details of active exploitation of CVE-2026-73570 were first highlighted by the Polish Computer Emergency Response Team (CERT Polska) in August 2026, with the agency urging users to review the "/var/log/zimbra.log" file for suspicious Zimbra service restarts, and look for files created in temporary and Zimbra "webapps" directories.
Later that month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies apply the fixes by August 24, 2026.
Based on telemetry data, the attack activity documented by Microsoft was identified "during the interval" between July 20, 2026, when Zimbra version 10.1.20 was released, and August 13, 2026, when the flaw was publicly disclosed.
Specifically, between July 28 and August 7, 2026, two distinct out-of-band scanning tools were found probing the injection path to validate command execution without delivering a follow-on payload.
The attackers then abused this initial access pathway to run commands as the "zimbra" service account and deploy multiple JSP web shells across Jetty and mailboxd application paths for redundancy, as well as download and execute malicious payloads directly through wget or curl, and establish interactive reverse shells.

"Other execution chains used cron, systemd, or memfd_create to maintain recurring or memory-backed execution," Microsoft said. "In some cases, attackers temporarily enabled write access to a public directory to deploy the web shell and then restored the directory permissions, limiting the visibility of the change during basic permission checks."
Some of the subsequent steps undertaken by the threat actor are listed below -
- Map the Zimbra deployment using zmprov to identify mailbox and MTA nodes for environment discovery.
- Check for the presence of the Zimbra SSH identity to likely facilitate movement between Zimbra hosts.
- Use a privilege-escalation technique that grants the "zimbra" service account unrestricted and passwordless sudo access by modifying the "/etc/pam.d/sudo" configuration file.
- Create a systemd service named "zimlog.service" for a second persistence mechanism that establishes execution at system boot.
- Target Zimbra's centralized service and authentication secrets by using the "zmlocalconfig -s" command on the server rather than going after individual mailbox passwords. The recovered credentials are then used for authenticated LDAP queries to retrieve high-value attributes, such as zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret.
- Utilize Zimbra's existing SSH identity at "/opt/zimbra/.ssh/zimbra_identity" to enable lateral movement across other trusted nodes in the cluster. Rsync is used to transfer JSP web shells and other helper scripts between nodes.
- Employ an OpenSSL-encrypted reverse shell to attacker-controlled infrastructure to conduct command execution, payload retrieval, and exfiltration of command output.
In at least one campaign, the attackers have been found to use a lightweight shell downloader for a Zimdown2 Go binary that then acts as an installer for the Zimclient2 remote-access agent. Zimclient2 offers interactive shell access, bidirectional file operations, and SOCKS5 proxying.
"It supported WebSocket, TLS, and raw TCP transports, providing resilient remote access and potential network pivoting through compromised Zimbra servers," Microsoft said. "Evidence identified several persistence mechanisms associated with the payload, including systemd services, OpenRC, cron, shell startup files, SSH authorized keys, and local account creation."
Also associated with the activity is the deployment of Zimbra-specific payloads. This includes a Go-based executable that attempts to extract Zimbra service-account credentials from "/opt/zimbra/conf/localconfig.xml," and use these values to construct MySQL and LDAP connection strings to the Zimbra MySQL instance and export the contents of the following database tables -
- mailbox
- mailbox_metadata
- mobile_devices
- out_of_office
- All tables in the zimbra.* namespace
The implant also collects and stages credential, certificate, LDAP secret, mail-rule, and configuration artifacts. The harvested files are compressed into a ZIP archive for subsequent transfer to a remote endpoint.
"On one compromised Zimbra server, the actor archived recent mailbox-backup content into /opt/zimbra/final.tar.gz," Microsoft said. "The actor then downloaded AzCopy from hxxps://aka[.]ms/downloadazcopy-v10-linux and invoked it with an operator-supplied Azure Blob SAS URL targeting wsweb03[.]blob[.]core[.]windows[.]net/log/windows.log."
"This activity shows mailbox-data collection, local archive staging, and an exfiltration attempt using cloud-storage tooling; available evidence does not confirm that the transfer completed successfully."
To counter the threat, organizations are advised to apply the updates immediately. If patching is not an option, it's recommended to uninstall the zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts only. Other safeguards include rotating Zimbra authentication secrets, scanning the server for redundant web shell persistence.