Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets
Microsoft details active exploitation of Zimbra CVE-2026-73570 unauthenticated command injection granting root access, web shells, and theft of mailbox authentication secrets.
CVE-2026-73570 is a high-severity unauthenticated OS command injection in Zimbra Collaboration Suite's SNMP notification path affecting versions before 10.1.20, which was patched July 20, 2026. Microsoft observed attackers probing the vulnerable path with OAST callbacks and a ZB73570 User-Agent between July 28 and August 7, before public disclosure on August 13. Successful intrusions deployed JSP web shells, escalated to root via PAM tampering with pam_exec, persisted through cron and a timestomped zimlog.service systemd unit, and moved laterally via SSH/rsync to cluster nodes. Attackers harvested LDAP credentials including zimbraPreAuthKey and zimbraAuthTokenKey to enable account takeover, used a Go implant to dump mailbox data, and attempted exfiltration via AzCopy to Azure Blob Storage; CISA added the CVE to its KEV catalog.
- Unauthenticated command injection in Zimbra SNMP path runs commands as zimbra account; fixed in 10.1.20
- Attackers probed the flaw pre-disclosure using OAST domains and CVE-specific ZB73570 User-Agent
- Privilege escalation via symlink to /etc/pam.d/sudo and pam_exec hook yields passwordless root sudo
- Go implant steals pre-auth keys and token keys enabling forged sessions for arbitrary accounts
- CISA added CVE-2026-73570 to KEV; rotate Zimbra pre-auth secrets after suspected intrusion
Vulnerabilities mentionedAll →
- CVE-2026-735708.972%Unauthenticated OS Command Injection RCE in Synacor Zimbra Collaboration Suitepublished · Synacor Zimbra Collaboration Suite (ZCS) KEV PoC ×5
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | dnslog.pp.ua | n interaction services such as oast[.]fun , oast[.]online , dnslog[.]pp[.]ua , and requestrepo[.]com . Attackers used lightweight co |
| domain | oast.fun | e, including domains hosted on interaction services such as oast[.]fun , oast[.]online , dnslog[.]pp[.]ua , and requestrepo[.]co |
| domain | oast.online | domains hosted on interaction services such as oast[.]fun , oast[.]online , dnslog[.]pp[.]ua , and requestrepo[.]com . Attackers us |
| domain | psk1zim.abrdns.com | -DNS domain Dropper C2, serving agent.sh/agent2.sh/zimdown2 psk1zim[.]abrdns[.]com/agentws Dynamic-DNS domain zimclient2 WebSocket (port 8 |
| domain | requestrepo.com | such as oast[.]fun , oast[.]online , dnslog[.]pp[.]ua , and requestrepo[.]com . Attackers used lightweight commands such as curl , wget |
| domain | transzimbra.linkpc.net | serving the build_amd64 cryptominer staged as .kworker_sys transzimbra[.]linkpc[.]net Dynamic-DNS domain Dropper C2, serving agent.sh/agent2. |
Full article875 words · extracted from gbhackers.com · click to collapse
An active exploitation of CVE-2026-73570, a high-severity unauthenticated OS command-injection vulnerability in Zimbra Collaboration Suite.
Attackers used to obtain root access, establish persistent control, and collect mailbox authentication secrets.
The issue resides in Zimbra’s SNMP notification processing path. An attacker can send a specially crafted SMTP request containing shell metacharacters, allowing attacker-controlled input to reach the swatchdog to snmptrap execution flow.
Improper input sanitization permits arbitrary commands to execute as the zimbra service account without authentication, user interaction, or a prior foothold. Zimbra Collaboration Suite versions earlier than 10.1.20 are affected.
Zimbra released version 10.1.20 on July 20, 2026, to address the vulnerability, but Microsoft observed attackers scanning and probing the vulnerable execution path between July 28 and August 7, before the vulnerability was publicly disclosed on August 13.
The timing indicates that threat actors either identified the patch gap independently or reverse-engineered the remediation before public disclosure.
The reconnaissance activity relied on out-of-band callback infrastructure, including domains hosted on interaction services such as oast[.]fun, oast[.]online, dnslog[.]pp[.]ua, and requestrepo[.]com.
Attackers used lightweight commands such as curl, wget, ping, nslookup, and id to validate command execution and confirm outbound connectivity before deploying payloads.
Microsoft also observed HTTP probes carrying a CVE-specific ZB73570 User-Agent.
Once exploitation succeeded, attackers used the zimbra account to change permissions on publicly reachable web directories and deploy JSP web shells across Jetty and mailboxd application paths.
The payloads were reconstructed from encoded and compressed fragments, while staging files were deleted afterward to reduce forensic traces.
Operators also downloaded second-stage payloads with wget or curl, created reverse shells, launched detached processes, and used cron, systemd, and memfd_create for recurring or memory-backed execution.

The intrusion progressed beyond web-shell persistence. Microsoft documented a privilege-escalation chain abusing legitimate Zimbra helpers, writable mailbox-manager logs, PAM configuration, pam_exec, and the zmstat-fd helper.
Attackers replaced a Zimbra log file with a symbolic link to /etc/pam.d/sudo, causing the PAM file to become writable by the zimbra account.
Zimbra Vulnerability Exploited
They then added a pam_exec hook that executed as root and created a passwordless sudo rule for the Zimbra user.
Microsoft Threat Intelligence identified that, the vulnerability affects internet-facing Zimbra servers running the optional zimbra-snmp package with SNMP notifications enabled.

This gave operators unrestricted root-level access while allowing them to restore much of the original PAM configuration and remove temporary artifacts.
The actors also established host persistence using a deceptive systemd unit named zimlog.service, placed in /etc/systemd/system/ and timestomped to resemble legitimate services.
In addition, the attackers leveraged Zimbra’s existing SSH identity, stored at /opt/zimbra/.ssh/zimbra_identity, to authenticate to trusted cluster nodes.
They used noninteractive SSH and rsync to move web shells, scripts, and payload fragments between mailbox servers, turning a single exposed system into a potential cluster-wide compromise.
Credential theft was especially concerning. The attackers ran zmlocalconfig -s to obtain Zimbra service credentials for LDAP, MySQL, Postfix, Amavis, and replication components.
Using recovered LDAP credentials, they queried sensitive attributes including zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret.
Possession of zimbraAuthTokenKey can enable the generation of signed session tokens for arbitrary accounts, while pre-authentication keys can facilitate pre-authenticated login URLs without requiring individual user passwords.
Microsoft also analyzed a Zimbra-focused Go implant, identified through the module path zimbra-exfil/client-dump, that reads /opt/zimbra/conf/localconfig.xml, extracts service-account passwords, queries local MySQL and LDAP services, and exports mailbox, mailbox metadata, mobile-device, out-of-office, and Zimbra namespace tables.
The tool staged collected data into timestamped directories under /tmp/ before compressing it for transfer.
In one confirmed case, attackers archived mailbox backup data into /opt/zimbra/final.tar.gz and attempted to transfer it with AzCopy to an Azure Blob Storage endpoint.
Microsoft said the evidence confirms archive staging and a transfer attempt, but does not establish that the exfiltration completed.
Administrators should urgently upgrade every Zimbra instance to version 10.1.20 or later.
Where immediate patching is impossible, organizations should remove the optional zimbra-snmp package if it is not required, disable SNMP notifications, and limit SNMP and SMTP exposure to trusted hosts.
Incident responders should treat reverse-shell activity on public-facing Zimbra servers as a priority compromise signal, inspect all mailbox nodes for JSP web shells and suspicious systemd units, and rotate Zimbra pre-authentication and session-token secrets after any suspected intrusion.
The vulnerability has also been added to CISA’s Known Exploited Vulnerabilities catalog, underscoring its operational urgency.
Indicators of compromise
| Indicator | Type | Role |
| 117.107.25[.]243:7071 | IPv4 (C2) | Dropper C2, serving de.sh |
| 192.255.193[.]111:9004 | IPv4 (C2) | Miner C2, serving the build_amd64 cryptominer staged as .kworker_sys |
| transzimbra[.]linkpc[.]net | Dynamic-DNS domain | Dropper C2, serving agent.sh/agent2.sh/zimdown2 |
| psk1zim[.]abrdns[.]com/agentws | Dynamic-DNS domain | zimclient2 WebSocket (port 80, /agentws) and raw TCP (8080) command channel |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.