AI Weekly Malaysia

Back to items Summaries

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

ID
30465
Status
summarized
Published
01 Oct 2026, 12:46 AM
Fetched
01 Oct 2026, 3:20 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
01 Oct 2026, 3:22 AM
Tags
Audience
developers

What happened

Microsoft Security Research documented exploitation of CVE-2026-73570 (CVSS 8.9), an unauthenticated OS command injection in Zimbra Collaboration Suite that is triggerable via a crafted SMTP request, but only when SNMP notifications are enabled and the optional zimbra-snmp package is installed. Post-exploitation activity between July 20 and August 13, 2026 included JSP web shells, reverse shells, privilege escalation, memory-backed execution, and collection of email, authentication and mailbox data. Zimbra patched the flaw in version 10.1.20 in July 2026; CERT Polska flagged active exploitation in August 2026 and CISA added it to the KEV catalog with an August 24, 2026 federal remediation deadline.

Why it matters

The reachability precondition is the decision point: if you or a client host Zimbra, check whether zimbra-snmp is installed and SNMP notifications are on - if not, this CVE is largely unreachable for you, and if you don't need it you can remove the package. If it is installed, confirm you are on 10.1.20 or later (patch shipped July 2026, before public disclosure on August 13) and grep /var/log/zimbra.log for suspicious service restarts plus temp and webapps directories for dropped files. For most Malaysian builders who don't self-host mail, this is not something to act on.

Discussion angle

CVSS 8.9 versus reachability: the flaw needs an optional SNMP package and non-default configuration, so should teams triage by score or by whether the component is actually deployed - and what does the July 20 patch / August 13 disclosure gap tell us about patching during silent-fix windows?

Top