Zimbra Flaw Exploited to Deploy Web Shells, Steal Credentials
Imazh i krijuar nga IA

Zimbra Flaw Exploited to Deploy Web Shells, Steal Credentials

Attackers are actively abusing a patched Zimbra command injection vulnerability to plant hidden backdoors and steal email authentication secrets, putting corpor…

A critical vulnerability in the Zimbra Collaboration Suite is being actively weaponised to seize control of email servers, according to the Microsoft Security Research team. The flaw, catalogued as CVE-2026-73570, allows unauthenticated attackers to inject operating system commands and execute malicious code remotely. This happens when Simple Network Management Protocol (SNMP) notifications are turned on and the optional zimbra-snmp package is installed. The vulnerability was patched by Zimbra in July 2026 with the release of version 10.1.20, but many internet-facing servers remain exposed.

The attack begins with a specially crafted email sent over the Simple Mail Transfer Protocol (SMTP), the standard for email transmission. This malicious message targets the vulnerable Zimbra server without any need for a password or user interaction. Once the specially formed request reaches the server, the command injection flaw lets the attacker run arbitrary system commands as the service account. Microsoft observed the first signs of probing activity between July 28 and August 7, 2026, when two distinct out-of-band scanning tools were seen testing the injection path to confirm remote code execution without yet delivering a full payload.

After gaining a foothold, the threat actors deploy multiple JavaServer Pages (JSP) web shells across different application directories. A web shell is a small piece of code that gives the attacker a browser-based control panel on the compromised server. By placing copies in both Jetty and mailboxd paths, the intruders ensure redundancy. They also use system tools like wget or curl to download additional malware and establish interactive reverse shells, which open a direct connection back to the attacker’s machine, bypassing firewalls. To stay hidden, some attackers briefly enable write access to a public directory, plant the web shell, and then restore the original permissions, making the change harder to spot during routine checks.

The post-exploitation activity is extensive. Attackers map the Zimbra environment using the zmprov command to identify mailbox and mail transfer agent nodes. They check for the Zimbra SSH identity key at /opt/zimbra/.ssh/zimbra_identity, which can be used to move laterally to other trusted servers in the cluster. Privilege escalation is achieved by modifying the /etc/pam.d/sudo configuration file to grant the zimbra service account unrestricted, passwordless sudo access. For persistence, they set up a systemd service called zimlog.service that triggers at boot, while other execution chains rely on cron jobs or memory-backed execution via memfd_create, a mechanism that runs code entirely in RAM to avoid leaving traces on disk.

A significant target is Zimbra’s centralised authentication data. The attackers run the command zmlocalconfig -s to extract service credentials, then use those for authenticated LDAP queries to harvest high-value secrets like zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret. With these, they can impersonate users or intercept authentication flows. They also leverage the SSH identity to move laterally across nodes, using rsync to transfer web shells and helper scripts. In at least one campaign, a lightweight downloader called Zimdown2 fetches a Go-based remote-access agent named Zimclient2, which offers an interactive shell, bidirectional file operations, and SOCKS5 proxying – effectively turning the compromised server into a pivot point for deeper network intrusion.

Data theft goes further. A separate Go executable extracts Zimbra service-account credentials from the local configuration file and constructs connection strings for the relational database used by Zimbra and LDAP. It then exports the contents of several database tables, including mailbox metadata, mobile device data, and all tables in the zimbra database namespace. Harvested files are compressed into a ZIP archive. In one instance, the actor archived recent mailbox-backup content and downloaded Microsoft’s AzCopy tool from an official URL to exfiltrate data to an Azure Blob Storage endpoint using a shared-access signature URL. Microsoft notes that available evidence does not confirm the transfer completed successfully, but the activity shows a clear intent to steal mailbox contents.

The activity was first publicly flagged by the Polish Computer Emergency Response Team (CERT Polska) in August 2026, which urged administrators to check logs for suspicious service restarts and look for unexpected files in temporary and webapps directories. Later that month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch by August 24, 2026. Microsoft’s telemetry identified the documented attack activity during the interval between the patch release on July 20, 2026 and the public disclosure on August 13, 2026. The identity of the attackers remains unknown.

For website owners and businesses running their own email infrastructure, this incident underscores the danger of unpatched collaboration software. Zimbra servers often sit at the boundary between the internet and internal networks, making them a high-value target. Applying updates immediately is essential, but if patching is impossible, uninstalling the zimbra-snmp package, disabling SNMP notifications, and restricting SMTP and SNMP access to trusted hosts are effective stopgaps. Organisations should also rotate all Zimbra authentication secrets and thoroughly scan for web shells. For those who lack in-house expertise, engaging a security-focused IT infrastructure service, such as AEU-I, can help ensure that patches are applied promptly, unusual server behaviour is monitored, and response procedures are in place before attackers strike.

Si të Mbroheni

  1. Ask your IT team to immediately update your Zimbra email server to version 10.1.20 or later, which fixes this flaw.
  2. If you manage your own Zimbra server and cannot install the update right away, uninstall the zimbra-snmp package and disable SNMP notifications to remove the vulnerable component.
  3. Restrict external access to your email server’s SNMP and SMTP ports (161, 162, and 25) so that only trusted IP addresses can reach them.
  4. Change all Zimbra authentication secrets and passwords, especially if your server might have been exposed, and enable two-factor authentication for all email accounts.
  5. Scan your server for unexpected files in the Zimbra webapps and temporary directories, and look for new system services or cron jobs that could indicate a web shell or backdoor.
  6. If you are not sure how to check your server, ask your hosting provider or a security professional to audit your Zimbra installation for signs of compromise.

Dobësitë & Zgjidhjet

Termat e Shpjeguar

  • SNMP (Simple Network Management Protocol) A protocol used to monitor and manage network devices; when not needed, leaving it enabled can open a door for attackers.
  • SMTP (Simple Mail Transfer Protocol) The standard technology that moves email across the internet; a specially crafted email can sometimes trick a server into running harmful commands.
  • command injection A security weakness that lets an attacker sneak system-level orders into a program, often through a web form or email, to take control of the server.
  • web shell A small hidden piece of code that gives an attacker a remote control panel inside a compromised website or server, usually accessed through a normal browser.
  • JSP (JavaServer Pages) A technology for building dynamic web pages; attackers use it to create disguised control panels that blend in with legitimate server files.
  • reverse shell A stealthy connection that a compromised server makes back to an attacker’s computer, allowing the attacker to type commands as if they were sitting at the keyboard.
  • lateral movement The technique of hopping from one compromised computer to another inside a network to reach more valuable targets or data.
  • LDAP (Lightweight Directory Access Protocol) A system that stores user accounts and passwords centrally; attackers query it to steal login secrets from many users at once.

Shërbime AEU të lidhura

  • AEU-I Konsulencë IT dhe sigurie