Zimbra Email Servers Under Active Attack: Patch Now to Block Web Shells and Data Theft
Microsoft's security research team has found threat actors actively exploiting a now-patched vulnerability in Zimbra Collaboration Suite (ZCS), tracked as CVE-2026-73570, to break into email servers. The flaw allows unauthenticated remote code execution via a specially crafted email, but only affects servers with SNMP notifications enabled and the optional zimbra-snmp package installed. Zimbra fixed the issue in version 10.1.20, released in July 2026.
Once inside, attackers deployed web shells and reverse shells, escalated privileges, installed persistent remote access tools, and ran code directly in memory to avoid leaving files behind. Microsoft observed victims across multiple regions and industries, with attackers accessing email accounts, harvesting authentication credentials and mailbox contents, and packaging stolen data into archives for transfer out of the network. It is not yet known who is responsible.
The issue was first flagged publicly by Poland's CERT in August 2026, which advised checking Zimbra logs for unexplained service restarts and unusual files in temporary and webapps directories. CISA later added the flaw to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to patch by 24 August 2026. Microsoft's telemetry shows scanning and exploitation activity occurring between late July and mid-August 2026, even before the flaw was publicly disclosed.