Microsoft is warning of active cyberattacks against organizations using Zimbra Collaboration Suite (ZCS), as cybercriminals are exploiting a serious security vulnerability to gain initial access to email servers. The attacks include installing malicious remote access tools, intercepting data from mailboxes , and creating mechanisms that allow attackers to maintain a presence on compromised systems.

According to the Microsoft Security Research, the activity concerns the vulnerability CVE-2026-73570, with a CVSS score of 8.9, which allows for the injection of operating system commands without prior authentication. Although Zimbra has already released a patch, the case highlights the risks organizations face when email servers remain exposed or are not updated in a timely manner.
How the CVE-2026-73570 vulnerability works
The security issue is related to certain configurations of Zimbra Collaboration Suite, when SNMP (Simple Network Management Protocol) notifications are enabled and package is installed zimbra-snmp.
Under these conditions, a remote attacker can exploit the processing of a specially crafted SMTP request, causing the server to execute unauthorized commands . SMTP is a core protocol for transporting email messages, which makes it particularly important to control the exposure of related services to the Internet.
The critical element is that the attack does not require valid credentials or any action from the recipient, so a vulnerable and accessible server can be targeted without a user account being compromised.
See also: Zimbra: Critical vulnerability in Classic Web Client requires immediate upgrade
Zimbra addressed the issue with the release of version 10.1.20in July 2026. For administrators, installing the patched version and verifying the actual state of services are key mitigation steps.
Web shells, reverse shells and gaining remote access
Microsoft found that the attackers did not limit themselves to the initial exploitation of the vulnerability. On some systems, they installed JSP web shells, i.e. malicious files that allow commands to be executed via web requests, as well as reverse shells, which create a connection from the compromised system to infrastructure controlled by the attacker.
These mechanisms can be used to administer the system, execute additional commands, and download new malicious files. Installing more than one web shell in different application paths, such as those associated with Jetty and mailboxd, also increases the chances of maintaining access even if one of the malicious files is detected and removed.
At the same time, the attackers reportedly used tools such as wget and curl to download additional payloads, while in some cases they exploited mechanisms for executing code in memory. The latter technique can reduce the traces left on the disk, making it difficult to detect the activity with traditional monitoring methods.
Microsoft has identified incidents across organizations across industries and geographies. However, not all compromised computers exhibited the same chain of events, and the identity of the perpetrators remains unknown.
Privilege escalation and lateral movement in the network
After the initial breach, the attackers attempted to gain broader control of the infrastructure. According to Microsoft's findings, they used the command zmprov to map the Zimbra installation and locate mailbox and mail transport (MTA) nodes.
They also looked for available SSH identitiesthat could facilitate the migration from a compromised server to other trusted nodes in the same environment. This technique, known as lateral movement, allows attackers to expand their presence without having to re-exploit the initial vulnerability on each machine.
In some cases, attempts at privilege escalation, security configuration modifications, and the creation of systemd services to automatically restart malicious processes were also documented. In addition, mechanisms such as cron and shell startup files were used to maintain access across reboots.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Zimbra vulnerability exploited for remote code execution

The importance of these actions is that simply patching the vulnerability is not necessarily enough to fully restore a system that has already been compromised. If web shells, unauthorized SSH keys, or malicious services remain active, attackers may still have access.
Zimdown2 and Zimclient2: Tools for continuous access
Of particular interest is the use of the Zimdown2 and Zimclient2, which were detected in at least one campaign. Zimdown2, a downloader written in Go, was used to install Zimclient2, a remote access.
This tool offers interactive shell access, file transfer functions, and SOCKS5 proxying capabilities. It also supports communication over WebSocket, TLS, and plain TCP, allowing for connection to remote infrastructure and the use of compromised servers as intermediate nodes.
Researchers identified multiple mechanisms for maintaining access, including systemd and OpenRC services, cron jobs, authorized SSH keys, and local account creation. The combination of different techniques makes it more difficult to completely eliminate the threat.
Credentials and data from mailboxes targeted
The attack is not limited to remote command execution. One of the most significant findings concerns the attempt to recover Zimbra secrets and access its databases.
A specially crafted malicious executable looked for service credentials file localconfig.xml in the and attempted to connect to MySQL and LDAP databases. In doing so, the attackers targeted data related to mailboxes, metadata, mobile devices, and autoresponder settings, as well as other elements of the zimbra.* namespace .
The data collected included credentials, certificates, LDAP secrets, and mail-rules. It was then archived for possible transfer outside the organization.
In one incident, Microsoft observed the creation of the file /opt/zimbra/final.tar.gz, which contained recent mailbox backup data. This was followed by the use of the AzCopy and an Azure Blobin an attempt to extract the data. It was not confirmed that this transfer was successful.
Warnings and protective measures
The activity was flagged by the Polish CERT Polska team in August 2026, while CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) list, asking federal agencies to implement the fixes by August 24, 2026.
See also: Zimbra zero-click exploit: Russian group steals emails and 2FA codes via CVE-2025-66376

Organizations using Zimbra should verify that they have installed the patched version and investigate any evidence of a previous breach. file /var/log/zimbra.log, looking for suspicious files in temporary directories and application paths, and checking for unauthorized services and SSH keys are important steps.
If immediate updating is not possible, it is recommended to consider disabling SNMP and removing the optional zimbra-snmp, where this is safe and compatible with the operation of the installation. Access to SMTP and SNMP services should also be limited to essential, trusted nodes.
Finally, in the event of a confirmed breach, it is necessary to change the secrets and credentials that may have been exposed, investigate possible lateral movement , and check for access retention mechanisms. The case reminds us that protecting an email server does not end with the installation of a patch: it also requires checking for signs of intrusion and an organized remediation process.
