VYPR
researchPublished Sep 30, 2026· 1 source

Unauthenticated Command Injection in Zimbra Collaboration Suite Exploited in the Wild

Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite, impacting internet-facing mail servers.

Microsoft Threat Intelligence has identified and is tracking the exploitation of CVE-2026-73570, a critical unauthenticated OS command injection vulnerability affecting the Zimbra Collaboration Suite. This flaw resides within the SNMP notification path of the software. Exploitation is possible through a specially crafted email sent to internet-facing Zimbra servers, provided the optional zimbra-snmp package is installed and SNMP notifications are enabled. Crucially, the attack requires no authentication and no user interaction to succeed.

Successful exploitation allows attackers to gain significant control over compromised servers. Observed malicious activities include the deployment of JavaServer Pages (JSP) web shells and reverse shells, enabling persistent remote access. Threat actors have also been observed accessing sensitive email data, collecting authentication credentials, and exfiltrating mailbox contents. The attacks have involved both automated payload delivery and hands-on-keyboard operations by adversaries.

The vulnerability, CVE-2026-73570, allows an attacker to inject shell metacharacters into an SMTP request, which are then processed by Zimbra's SNMP notification system. If the input is not properly sanitized, embedded commands can be executed with the privileges of the zimbra service account. The vulnerability was publicly disclosed on August 13, 2026, but Microsoft telemetry indicates that exploitation attempts began as early as July 28, 2026, after a fix was available on July 20, 2026, in Zimbra version 10.1.20.

Prior to the public disclosure, Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point between July 28 and August 7. These probes used lightweight requests to validate command execution by checking local identity or dropping small scripts, often using collaborator services for callback verification. This reconnaissance phase demonstrated the attackers' intent to confirm exploitability before launching full-scale attacks.

The attack chain typically begins with a crafted SMTP request that triggers the command injection. Attackers then leverage this initial access to deploy JSP web shells. This often involves modifying webroot permissions, reconstructing encoded payloads from fragments, and writing them to publicly accessible directories. In some instances, attackers downloaded and executed content directly using tools like wget or curl, or established interactive reverse shells.

Persistence mechanisms varied, with attackers employing cron jobs, systemd services, or memory-backed execution techniques like memfd_create. Multiple JSP web shells were deployed across different application paths, including Jetty and mailboxd, to ensure continued access and resilience against detection. Attackers also took steps to limit the visibility of their actions, such as temporarily enabling write access to public directories and then restoring original permissions.

Post-exploitation, attackers focused on reconnaissance within the compromised environment. They utilized Zimbra's zmprov tool to map server roles and identify mailboxes and Mail Transfer Agents (MTAs). Additionally, they checked for existing administrative trust through Zimbra SSH identities to facilitate lateral movement within the network. DNS-based callbacks were used to exfiltrate environment details, including server counts and other system information.

Microsoft observed affected organizations across multiple regions and industries, indicating a widespread impact. The observed activity was not confined to a single sector or geographic area, highlighting the broad applicability of this vulnerability. The analysis combines behaviors observed across various confirmed compromises, with no single host exhibiting every stage of the attack chain.

Synthesized by Vypr AI