**Critical Zimbra Flaw Exploited for Remote Access and Data Theft**
A high-severity security vulnerability in the Zimbra Collaboration Suite has been weaponized by malicious actors to deploy web shells, steal email data, and establish persistent backdoors within compromised networks.
The security hole, identified as CVE-2026-73570, is rated 8.9 on the Common Vulnerability Scoring System (CVSS). It is an unauthenticated operating system command injection flaw that targets the Simple Network Management Protocol (SNMP) notification feature. When the optional zimbra-snmp component is installed, attackers can trigger the vulnerability by sending a specially crafted email to an exposed server, achieving remote code execution without requiring authentication or any user interaction. The software vendor released a patch for the flaw in its version 10.1.20 update in July 2026.
Cybersecurity experts first documented the active abuse of this flaw in August 2026, warning administrators to look for suspicious service restarts and unauthorized files in temporary directories. Shortly after, the flaw was added to a prominent government catalog of actively exploited vulnerabilities, mandating that federal agencies apply the fixes within a strict timeframe.
Investigations into the exploitation window revealed that malicious activity occurred between the release of the patch and the public disclosure of the flaw. Threat actors probed the injection path to validate command execution, and once confirmed, they executed commands under the service account. The attackers deployed redundant JSP web shells across multiple application paths, downloaded and executed malicious payloads, and established interactive reverse shells for ongoing control.
The threat actors employed several advanced tactics to escalate privileges and maintain persistence. They modified system configurations to grant passwordless administrative access and created custom services designed to execute at system boot. Using built-in administrative tools, the attackers mapped the internal deployment, extracted centralized authentication credentials, and moved laterally between trusted servers using SSH keys. They also deployed a custom remote-access tool offering encrypted communication channels, bidirectional file transfers, and network proxying capabilities.
In targeted campaigns, the attackers archived email data and attempted to exfiltrate it to external cloud storage environments, while also harvesting authentication tokens and system configuration artifacts.
To defend against these attacks, organizations are urged to apply the latest updates immediately. If patching is not feasible, administrators should remove the zimbra-snmp package, disable SNMP notifications, and restrict access to SNMP and SMTP protocols to trusted hosts only. Additional recommended safeguards include resetting all authentication secrets and scanning servers for unauthorized web shells and suspicious configuration changes.
***
**FAQ**
**What is CVE-2026-73570?**
CVE-2026-73570 is an unauthenticated operating system command injection vulnerability found in Zimbra Collaboration Suite. It allows remote attackers to execute arbitrary commands on a server by exploiting the SNMP notification feature when the zimbra-snmp package is installed.
**How do attackers exploit this vulnerability?**
The flaw can be triggered by sending a specially crafted SMTP request—essentially a malicious email—to an exposed Zimbra server. No authentication or user interaction is required to trigger the vulnerability.
**What happens after a server is compromised?**
Once access is gained, attackers deploy web shells for persistent access, escalate privileges to gain unrestricted administrative control, and extract sensitive credentials and mailbox data. They also use the compromised server to move laterally across the network.
**What is the Zimclient2 tool mentioned in the attacks?**
Zimclient2 is a Go-based remote-access agent used by the threat actors. It provides interactive shell access, file operations, and network proxying capabilities, supporting multiple encrypted communication protocols to maintain resilient control over compromised servers.
**Who is at risk?**
Any organization running an unpatched version of Zimbra Collaboration Suite with the SNMP notification feature enabled is at risk. The vulnerability has been observed affecting organizations across multiple industries and regions.
***
**Conclusion**
The exploitation of CVE-2026-73570 highlights the severe risks associated with delaying security patches, particularly for high-severity vulnerabilities in widely used collaboration platforms. By quickly applying updates, disabling unnecessary protocols like SNMP, and maintaining strict network segmentation, organizations can effectively block these attacks and protect their sensitive email data from unauthorized access.
Thank you for reading



