Attackers have weaponized a recently patched security vulnerability in Zimbra Collaboration Suite to install web shells and steal mailbox information, according to findings from the Microsoft Security Research team. The exploit targets CVE-2026-73570, an unauthenticated command injection flaw with a severity score of 8.9 that allows remote code execution when Simple Network Management Protocol notifications are turned on and the optional zimbra-snmp package is present. The vulnerability can be triggered through a specially crafted email sent to exposed Zimbra servers without requiring authentication or user interaction, and Zimbra released a patch in July 2026 with version 10.1.20.

Microsoft identified compromised organizations across multiple regions and industries, though not every affected system showed every stage of the attack sequence. The attack activity occurred between July 20, 2026, when Zimbra version 10.1.20 was released, and August 13, 2026, when the flaw became publicly known. During a narrower window from July 28 to August 7, 2026, two separate out-of-band scanning tools probed the injection pathway to validate command execution without delivering follow-on payloads. Polish Computer Emergency Response Team first highlighted active exploitation in August 2026, prompting the U.S. Cybersecurity and Infrastructure Security Agency to add the flaw to its Known Exploited Vulnerabilities catalog and mandate federal agencies apply fixes by August 24, 2026.

Following successful compromise, the tech giant observed deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution. Threat actors accessed email and collected authentication and mailbox data, with archive creation and transfer activity observed. Attackers abused initial access to run commands as the zimbra service account and deploy multiple JSP web shells across Jetty and mailboxd application paths for redundancy. The threat actors also downloaded and executed malicious payloads directly through wget or curl, established interactive reverse shells, and used cron, systemd, or memfd_create to maintain recurring or memory-backed execution. In some instances, attackers temporarily enabled write access to a public directory to deploy the web shell before restoring directory permissions to limit visibility during basic permission checks.

The report details how attackers mapped Zimbra deployments using zmprov to identify mailbox and MTA nodes, checked for Zimbra SSH identity to facilitate movement between hosts, and modified the /etc/pam.d/sudo configuration file to grant the zimbra service account unrestricted and passwordless sudo access. The threat actors targeted Zimbra's centralized service and authentication secrets using the zmlocalconfig -s command rather than pursuing individual mailbox passwords, then used recovered credentials for authenticated LDAP queries to retrieve high-value attributes including zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret. In at least one campaign, attackers deployed a lightweight shell downloader for a Zimdown2 Go binary that acted as an installer for the Zimclient2 remote-access agent, which offered interactive shell access, bidirectional file operations, and SOCKS5 proxying through WebSocket, TLS, and raw TCP transports. The implant also collected and staged credential, certificate, LDAP secret, mail-rule, and configuration artifacts, compressing them into a ZIP archive. On one compromised server, the actor archived recent mailbox-backup content and downloaded AzCopy from a Microsoft endpoint before invoking it with an operator-supplied Azure Blob SAS URL, though available evidence doesn't confirm the transfer completed successfully.

Organizations are advised to apply updates immediately, or if patching isn't an option, uninstall the zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts only. Other safeguards include rotating Zimbra authentication secrets and scanning servers for redundant web shell persistence. The identity of the threat actors remains unknown. The incident reveals how quickly adversaries can capitalize on disclosed vulnerabilities in widely deployed collaboration platforms, particularly when optional features create unexpected attack surfaces. Organizations running complex email infrastructure face mounting pressure to balance feature availability against the expanded risk profile that comes with every additional service component.