Microsoft Warns of Critical Zimbra Command Injection Flaw


zimbra exploit
Image credit: Zimbra

Microsoft Threat Intelligence is tracking a critical Zimbra Collaboration Suite vulnerability that attackers are actively exploiting against internet-facing mail servers.

The flaw, tracked as CVE-2026-73570, affects the Zimbra Collaboration Suite SNMP notification path and allows unauthenticated attackers to execute operating system commands remotely.

Attackers can trigger the vulnerability using specially crafted SMTP requests when zimbra-snmp is installed and SNMP notifications are enabled.

Successful exploitation gives attackers remote command execution using Zimbra service account privileges without requiring any user interaction.

Zimbra patched the flaw in July

Zimbra fixed the vulnerability in version 10.1.20, released on July 20, 2026.

However, Microsoft telemetry shows attackers were already probing and exploiting vulnerable systems between the patch release and the vulnerability’s public disclosure on August 13.

That gave threat actors a window to target organizations that had not yet installed the update.

Attackers can steal authentication keys and tokens

Microsoft says attackers can use CVE-2026-73570 to obtain sensitive authentication information from compromised Zimbra systems.

That information can include pre-authentication keys and session tokens, potentially allowing attackers to maintain access to affected organizations even after the initial compromise.

Threat actors can also combine the vulnerability with additional malicious payloads and legitimate service components to bypass defenses and escalate privileges.

Attackers are installing multiple webshells

Microsoft observed attackers deploying several JSP webshells across Jetty and mailboxd application directories after compromising vulnerable servers.

Attackers also placed additional copies of the webshells on peer mailbox nodes. This gives them several alternative access points and reduces their dependence on a single backdoor.

Microsoft Defender detected the attacks

Microsoft says Defender detected malicious activity across every attack path the company observed.

Defender identified SNMP command injection attempts and detected or quarantined payloads including Chopper, GodzillaWebShell, CoinMiner, Looptik, SuspGoLang, and Ditelti.

The security platform also detected suspicious permission changes, background execution activity, and malicious files being dropped and launched.

Administrators should update Zimbra immediately

Microsoft recommends that administrators upgrade affected systems to Zimbra 10.1.20 or later as soon as possible.

Organizations that do not use SNMP functionality should also uninstall the zimbra-snmp package to remove the vulnerable attack surface.

Administrators should restrict SNMP and SMTP access where possible and review exposed Zimbra systems for signs of compromise.

Security teams can also use Microsoft’s provided Microsoft Defender XDR Kusto queries to search for suspicious swatchdog script executions and unauthorized file modifications.

In other security news, Microsoft is blocking injected scripts on Entra ID sign-ins and introducing a new Windows 11 26H2 security baseline.

A separate campaign also uses a fake ChatGPT Plus 5.6 page to install RAT malware.

More about the topics: Cybersecurity, email, microsoft

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages