Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Executive Summary
Threat actors weaponized a patched CVE-2026-73570 in Zimbra Collaboration Suite, enabling unauthenticated OS command injection that leads to remote code execution via SNMP. Attackers deployed web shells and extracted mailbox authentication secrets, as reported by Microsoft Security Research.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-30T16:46:29+00:00 - Category: threat-intel
Original Description: Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol
"You, yourself, as much as anybody in the entire universe, deserve your love and affection."
— Buddha