Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
thehackernews.com Sep 30, 2026

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

AI-summarised brief · reviewed before publication

Microsoft Security Research identified that threat actors exploited the CVE‑2026‑73570 command‑injection flaw in Zimbra Collaboration Suite, enabling remote code execution via unauthenticated SMTP requests. After Zimbra patched the vulnerability in July 2026, attackers deployed JSP web shells, reverse shells, and persistent tools, then harvested mailbox data, authentication secrets, and configuration files. The activity spanned multiple regions and industries, with evidence of credential extraction, database dumping, and data exfiltration. The U.S. CISA added the flaw to its KEV catalog, mandating federal fixes by August 24, 2026.

💡 Why It Matters

  • · The breach demonstrates how quickly a patched vulnerability can be weaponized, exposing critical email infrastructure to data theft and remote control.
  • · It underscores the urgency for organizations to monitor logs and enforce timely patching to protect sensitive communications.