No Password Needed as Hackers Break Into Zimbra Servers

The420.in Staff
6 Min Read

Cyber attackers are exploiting a critical security vulnerability in Zimbra Collaboration Suite (ZCS) to break into email servers, deploy web shells and reverse shells, maintain persistent access and attempt to steal sensitive email and authentication data. Security research has also found cases where stolen information was archived on compromised servers and prepared for exfiltration.

How Are Attackers Breaking Into Zimbra Servers?

The attacks exploit CVE-2026-73570, a vulnerability with a CVSS score of 8.9. It is an unauthenticated operating system command-injection flaw that can lead to remote code execution under specific conditions. Exploitation requires SNMP notifications to be enabled on the Zimbra server and the optional “zimbra-snmp” package to be installed. Attackers can trigger the vulnerability through specially crafted SMTP requests without requiring user interaction.

Zimbra patched the vulnerability in July 2026 with the release of version 10.1.20. Despite the availability of the update, attacks have continued against servers that were not patched or remained vulnerable. Security researchers observed affected organizations across more than one region and industry, although not every compromised host displayed every stage of the attack chain. The identity of the attackers remains unknown.

Details of active exploitation emerged in August. The U.S. cybersecurity agency subsequently added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog and set August 24, 2026, as the deadline for federal agencies to apply the fix. Telemetry indicates that attack-related activity was observed between July 20 and August 13.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

How Did Attackers Maintain Access?

Between July 28 and August 7, two separate scanning tools were detected probing the Zimbra command-injection path. The tools were used to determine whether commands could be executed on vulnerable servers before delivering additional malicious payloads. Attackers subsequently used the initial access to execute commands under the “zimbra” service account and install multiple JSP web shells across Jetty and mailboxd application paths. Deploying multiple web shells provided redundant access if one of the malicious files was discovered and removed.

Attackers also used “wget” and “curl” to download and execute malicious payloads and established interactive reverse shells. In some cases, cron, systemd and memory-backed execution techniques were used to maintain recurring or persistent access. In one instance, attackers temporarily modified permissions on a public directory to make it writable, deployed a web shell and then restored the original permissions, potentially reducing the visibility of the change during routine checks.

The attackers used “zmprov” to map the Zimbra environment and identify mailbox and mail-transfer nodes. They also searched for Zimbra’s SSH identity to facilitate movement between trusted servers within the cluster. In one privilege-escalation technique, the attackers modified “/etc/pam.d/sudo” to give the “zimbra” service account unrestricted, passwordless sudo access. They also created a systemd service named “zimlog.service” to establish another persistence mechanism that could execute when the system started.

What Authentication Secrets Were Targeted?

A key objective of the attack was to obtain Zimbra’s centralized authentication secrets. Instead of targeting individual mailbox passwords, attackers used “zmlocalconfig -s” to retrieve sensitive server-level information. The recovered credentials could then be used for authenticated LDAP queries to obtain high-value authentication attributes, including “zimbraPreAuthKey”, “zimbraAuthTokenKey” and “zimbraTwoFactorAuthSecret”.

Attackers also used Zimbra’s existing SSH identity to move to other nodes and transfer web shells and supporting scripts. Encrypted reverse shells were used to connect compromised servers to attacker-controlled infrastructure, enabling command execution, payload retrieval and the collection of command output.

What Data Did Attackers Try to Steal?

In one campaign, attackers deployed the Zimclient2 remote-access agent through a Go-based payload called Zimdown2. The tool provides interactive shell access, bidirectional file operations and SOCKS5 proxying. Other persistence methods identified during the activity included systemd services, OpenRC, cron jobs, SSH authorized keys and the creation of local accounts.

Attackers also deployed a Zimbra-specific payload designed to extract service-account credentials from “localconfig.xml”. The information was used to construct MySQL and LDAP connections and attempt to extract data from tables including “mailbox”, “mailbox_metadata”, “mobile_devices” and “out_of_office”. Other configuration, certificate, credential, LDAP secret and mail-rule files were also collected and compressed for possible exfiltration.

On one compromised Zimbra server, recent mailbox backup data was archived in “/opt/zimbra/final.tar.gz” and an attempt was made to transfer it using cloud-storage tooling. However, available evidence does not confirm that the transfer was completed successfully.

What Should Zimbra Administrators Do Now?

Organizations are advised to immediately update Zimbra to version 10.1.20 or a later secure release. If immediate patching is not possible, administrators should remove the “zimbra-snmp” package, disable SNMP notifications and restrict SNMP and SMTP access to trusted hosts. Authentication secrets should also be rotated, while servers should be thoroughly checked for hidden web shells, persistence mechanisms and other indicators of compromise.

The420 Takeaway

Installing the security update is critical, but organisations that operated a vulnerable Zimbra server should not assume patching alone resolves a previous compromise. Administrators should investigate for web shells and persistence, examine suspicious activity and rotate potentially exposed authentication secrets.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected