Particle.news

Microsoft Documents Active Exploitation of Critical Zimbra Remote‑Code Flaw

The report shows attackers ran unauthenticated commands through Zimbra's SNMP notification path to install web shells, stage mailbox archives, attempt cloud exfiltration

Overview

  • Zimbra issued a patch on July 20, 2026, for CVE-2026-73570, a command-injection bug that lets attackers run OS commands when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
  • Microsoft published detailed telemetry on September 30, 2026, showing early scans between July 28 and August 7 that validated command execution before operators delivered web shells and hands-on access.
  • Observed attacker actions included deploying JSP web shells and reverse shells, escalating privileges, harvesting Zimbra service-account credentials, and exporting mailbox-related database tables.
  • At least one operation staged mailbox backups into a local archive and invoked AzCopy with a supplied Azure SAS URL to try to move data to cloud storage, though Microsoft could not confirm the transfer completed.
  • Security teams and CISA advise immediate patching or removal of zimbra-snmp, disabling SNMP notifications, rotating Zimbra secrets, restricting SNMP/SMTP access, and hunting for web shells and persistence artifacts.