Full Report
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol
Analysis Summary
# Vulnerability: Unauthenticated OS Command Injection in Zimbra Collaboration Suite
## CVE Details
- **CVE ID:** CVE-2026-73570
- **CVSS Score:** 8.9 (High/Critical)
- **CWE:** OS Command Injection
## Affected Systems
- **Products:** Zimbra Collaboration Suite (ZCS)
- **Versions:** Versions prior to 10.1.20
- **Configurations:** Systems where Simple Network Management Protocol (SNMP) notifications are enabled and the optional `zimbra-snmp` package is installed.
## Vulnerability Description
CVE-2026-73570 is an unauthenticated operating system command injection flaw. It is triggered when a specially crafted SMTP request (email) is sent to an exposed Zimbra server. The flaw exists within the handling of SNMP notifications; if the `zimbra-snmp` package is active, the crafted request allows an attacker to execute arbitrary commands at the OS level with the privileges of the "zimbra" service account.
## Exploitation
- **Status:** Exploited in the wild (Added to CISA KEV catalog).
- **Complexity:** Low (Requires no authentication or user interaction).
- **Attack Vector:** Network (via SMTP).
## Impact
- **Confidentiality:** High (Access to mailboxes, LDAP queries, and authentication secrets like `zimbraPreAuthKey`).
- **Integrity:** High (Ability to deploy web shells, modify `sudo` configurations, and create systemd services).
- **Availability:** High (Potential for full system takeover and persistent remote access).
## Remediation
### Patches
- Upgrade Zimbra Collaboration Suite to **version 10.1.20** or later (Released July 2026).
### Workarounds
- Disable SNMP notifications if not strictly required.
- Uninstall or disable the `zimbra-snmp` package.
- Restrict SMTP traffic to trusted sources where possible, though this may impact mail delivery.
## Detection
- **Indicators of Compromise (IoCs):**
- Presence of JSP web shells in Jetty or `mailboxd` application paths.
- Creation of a systemd service named `zimlog.service`.
- Unauthorized modifications to `/etc/pam.d/sudo` (granting passwordless sudo to the zimbra user).
- Presence of malicious payloads downloaded via `wget` or `curl`.
- Suspicious use of `zmlocalconfig -s` or `zmprov` commands.
- **Detection Methods:**
- Review `/var/log/zimbra.log` for suspicious service restarts.
- Monitor for files created in temporary (`/tmp`) and Zimbra "webapps" directories.
- Audit `/opt/zimbra/.ssh/zimbra_identity` for unauthorized lateral movement activity.
## References
- Microsoft Security Research: hxxps[://]www[.]microsoft[.]com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
- The Hacker News: hxxps[://]thehackernews[.]com/2026/09/attackers-exploit-zimbra-flaw-to-deploy[.]html
- CERT Polska Advisory: hxxps[://]thehackernews[.]com/2026/08/attackers-exploit-zimbra-snmp-flaw-for[.]html