All stories
Security

Critical Zimbra Flaw Actively Exploited to Steal Emails and Compromise Systems

Zimbra Collaboration Suite'te kimlik doğrulaması gerektirmeyen kritik bir işletim sistemi komut enjeksiyonu güvenlik açığı (CVE-2026-73570) aktif olarak istismar edildi ve saldırganların basit bir SMTP isteğiyle e-postaları çalmasına ve temel sistemleri ele geçirmesine olanak tanıdı; bu durum, binlerce kuruluşun iletişim bütünlüğünü ciddi şekilde tehlikeye atarak acil yama ve güvenlik duruşu gözden geçirmesini zorunlu kılıyor.

By TECH NEWS Editorial·Source:Ars Technica·3 min read·1h ago

✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Critical Zimbra Flaw Actively Exploited to Steal Emails and Compromise Systems

A critical, unauthenticated operating system command injection vulnerability, identified as CVE-2026-73570 with a CVSS score of 8.9, has been actively exploited in the Zimbra Collaboration Suite (ZCS), allowing attackers to steal emails and compromise underlying systems through a simple, specially crafted SMTP request. This severe flaw impacts exposed Zimbra servers where the optional `zimbra-snmp` package is installed and SNMP notifications are enabled, granting remote attackers the ability to execute arbitrary commands without requiring any authentication or user interaction.

The exploitation window for CVE-2026-73570 was alarmingly narrow, with Zimbra releasing a patch in ZCS version 10.1.20 on July 20, 2026, nearly a month after the flaw was initially disclosed on June 26, 2026. However, active exploitation was detected by the Microsoft Security Research team during the interval between July 20 and August 13, 2026, when the flaw was publicly detailed. CERT Polska first highlighted active exploitation in August 2026, leading the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply fixes by August 24, 2026. Once exploited, threat actors have been observed deploying JSP web shells and reverse shells, escalating privileges, establishing persistent remote access, and crucially, accessing email and collecting authentication and mailbox data, including archiving mailbox-backup content for exfiltration. Shadowserver Foundation reported at least 274 internet-facing Zimbra instances were compromised by mid-August, with thousands of organizations globally, including nearly 700 in the U.S., still using vulnerable versions.

This vulnerability's significance extends far beyond typical data theft, fundamentally undermining the integrity of an organization's communications and potentially enabling a sophisticated form of Business Email Compromise (BEC). Unlike traditional BEC that relies on social engineering, this flaw allows attackers to directly manipulate the email infrastructure itself, impersonating senders, controlling inbox visibility, and altering shared documents and calendars. When the platform that serves as a system of record for who said what, and who agreed to be where, is compromised, it creates a "conflict of evidence" where fabricated context can lead to real business decisions based on attacker-controlled information. The sheer ease of exploitation, requiring only a crafted SMTP request without authentication, makes this a high-priority threat for any organization utilizing Zimbra.

Zimbra Collaboration Suite, while not commanding the dominant market share of giants like Microsoft Outlook (87.77%) or Google Workspace, holds a niche in the enterprise email client market with an estimated 1.96% share and over 6,800 customers, often favored by organizations seeking greater control over their data or more cost-effective alternatives to proprietary solutions. However, this isn't Zimbra's first encounter with critical security challenges. The platform has a history of attracting both state-sponsored hackers and opportunistic cybercriminals. In 2022, a high-severity vulnerability (CVE-2022-27924) allowed unauthenticated attackers to steal cleartext passwords by injecting arbitrary memcache commands. Another zero-day in 2022 saw over 1,000 Zimbra email servers hacked via a PGP decryption exploit. More recently in March 2026, a stored cross-site scripting (XSS) vulnerability (CVE-2026-33370) in the Briefcase feature allowed malicious script execution in user sessions. These recurring, severe vulnerabilities highlight a persistent challenge in securing Zimbra's complex architecture, particularly when compared to the more robust, centrally managed security postures often seen in cloud-native offerings from Microsoft and Google, which benefit from vast security research teams and rapid deployment of patches.

Looking ahead, the immediate imperative for all organizations running Zimbra Collaboration Suite is to urgently update to version 10.1.20 or later to mitigate CVE-2026-73570. Beyond patching, administrators must meticulously review Zimbra logs, particularly `/var/log/zimbra.log`, for suspicious service restarts, unauthorized file creations in temporary or webapps directories, and any signs of web shells or reverse shells, which indicate active compromise. The incident also serves as a stark reminder for organizations to re-evaluate their overall email security posture, particularly for self-hosted solutions. Proactive threat monitoring, robust input sanitization across all components, and a layered security approach including web application firewalls are no longer optional. This continuous cycle of critical vulnerabilities and rapid exploitation underscores the shrinking window for defenders, demanding not just timely patching but a fundamental shift towards a security-first operational mindset for collaboration platforms that are increasingly becoming the bedrock of enterprise operations.