Select a theme from the list.
Insights

From our experts

Latest
OpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelAI-Speed Intruder Chains Zammad Zero-Days Into Root AccessCrafted Emails Turn Zimbra Servers Into Command-Execution GatewaysRansomware Disrupts Business Systems at Major Japanese Railway GroupStolen Passwords Left French Tax Data Exposed for Seven WeeksCheap AI Decisions Could Create an Expensive Security ProblemApple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsOpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelAI-Speed Intruder Chains Zammad Zero-Days Into Root AccessCrafted Emails Turn Zimbra Servers Into Command-Execution GatewaysRansomware Disrupts Business Systems at Major Japanese Railway GroupStolen Passwords Left French Tax Data Exposed for Seven WeeksCheap AI Decisions Could Create an Expensive Security ProblemApple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer Workloads
Security Insight

Crafted Emails Turn Zimbra Servers Into Command-Execution Gateways

Crafted Emails Turn Zimbra Servers Into Command-Execution Gateways
Photo by Tima Miroshnichenko on Pexels

Microsoft has documented attacks exploiting CVE-2026-73570, an unauthenticated command-injection vulnerability affecting certain internet-facing Zimbra Collaboration Suite servers. Attackers used specially crafted SMTP traffic to install web shells, obtain root privileges, collect authentication secrets and attempt mailbox-data theft.

News Date: 2026-09-30

Internet-facing email infrastructure is once again demonstrating why it belongs near the top of every enterprise patching list. Microsoft has detailed real-world exploitation of CVE-2026-73570, a Zimbra Collaboration Suite vulnerability that can allow attackers to execute operating-system commands by sending specially crafted SMTP traffic.

An Email Can Trigger Server-Side Commands

The vulnerability exists in Zimbra's SNMP notification path. Exploitation requires the optional zimbra-snmp package to be installed and SNMP notifications to be enabled, but it does not require valid credentials or interaction from a user. A malicious request can introduce attacker-controlled input into a shell command executed under the Zimbra service account.

Microsoft observed reconnaissance and probing after Zimbra released version 10.1.20 on July 20, but before the vulnerability was publicly disclosed on August 13. The subsequent intrusions went far beyond simple vulnerability testing. Attackers installed multiple JSP web shells, opened reverse shells and used trusted relationships within Zimbra clusters to move between servers.

The Real Target Was the Trust Around Email

Compromised systems were searched for service credentials, authentication keys, two-factor authentication secrets and mailbox information. In some cases, attackers escalated to root by abusing legitimate Zimbra components and Linux authentication mechanisms. They also created disguised system services, manipulated timestamps and deployed remote-access agents with encrypted communications and proxy capabilities.

This is especially serious because a mail server is more than a message repository. It often holds password-reset emails, confidential conversations, legal records and authentication material. A compromised server may therefore become a platform for identity theft, internal phishing and movement into connected systems.

Recommended Defensive Actions

  • Upgrade every Zimbra instance to version 10.1.20 or later.
  • Remove zimbra-snmp or disable SNMP notifications if immediate patching is impossible.
  • Inspect web application directories for unexpected JSP files and compiled servlet artifacts.
  • Review system services, sudo configuration, SSH keys and recent permission changes.
  • Rotate Zimbra preauthentication keys, token-signing material and exposed service credentials.

In my view, organizations should treat evidence of a reverse shell as a confirmed breach rather than a blocked exploit attempt. Removing one payload is not enough when attackers may have installed several independent access methods. Full forensic scoping across every node in the Zimbra cluster is essential.

Talk to our team →

Latest

OpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelOct 1, 2026AI-Speed Intruder Chains Zammad Zero-Days Into Root AccessOct 1, 2026Crafted Emails Turn Zimbra Servers Into Command-Execution GatewaysOct 1, 2026Ransomware Disrupts Business Systems at Major Japanese Railway GroupSep 30, 2026Stolen Passwords Left French Tax Data Exposed for Seven WeeksSep 30, 2026Cheap AI Decisions Could Create an Expensive Security ProblemSep 30, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards