Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Burnham wants to change British elections. Voters think they’re fine as is. – POLITICO

    October 2, 2026

    Whatever AI Safety Is, It’s Not This

    October 2, 2026

    A Coding Guide to Google Research’s Kauldron: Configs That Are Plain Data, Components Wired by String, and a JAX Trainer You Can Read End to End

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Burnham wants to change British elections. Voters think they’re fine as is. – POLITICO
    • Whatever AI Safety Is, It’s Not This
    • A Coding Guide to Google Research’s Kauldron: Configs That Are Plain Data, Components Wired by String, and a JAX Trainer You Can Read End to End
    • Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
    • Frank Holmes: They Will Print $100 Trillion
    • A first in Brazil: Black-faced lion tamarins vaccinated
    • France Unveils 2027 Budget Amid Violent Student Protests
    • G20 trade ministers deadlocked over industrial overcapacity, says US trade chief
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 1, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers started exploiting a high-severity OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) shortly after patches were rolled out, before public disclosure, Microsoft reports.

    Tracked as CVE-2026-73570 (CVSS score of 8.9), the flaw exists because, in ZCS before 10.1.20, untrusted input during SNMP notification processing is improperly sanitized.

    Thus, if the zimbra-snmp package has been installed and SNMP notifications have been enabled, an attacker could trigger the security defect via specially crafted SMTP requests.

    Successful exploitation of the bug allows unauthenticated attackers to achieve remote code execution with the privileges of the Zimbra user.

    Patches for CVE-2026-73570 were rolled out on July 20 in ZCS version 10.1.20, and the vulnerability was publicly disclosed on August 13.

    Poland’s CERT Polska flagged the security defect as exploited and released indicators of compromise (IoCs) on August 17, but in-the-wild exploitation started between patching and public disclosure.

    Advertisement. Scroll to continue reading.

    “Between July 28 and August 7, after a fix became available on July 20 but before public disclosure on August 13, Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point,” Microsoft says.

    The reconnaissance activity used an execution path that was later seen during exploitation, and was meant to validate command execution via lightweight out-of-band probes, without delivering a payload.

    As part of the observed follow-up exploitation activity, the attackers deployed JSP webshells to publicly accessible application directories, executed content through wget or curl, launched background processes, and established interactive reverse shells.

    “Multiple JSP webshells were deployed across Jetty and mailboxd application paths, including additional copies on peer mailbox nodes. This provided alternative access paths across different Zimbra configurations and reduced reliance on a single webshell,” Microsoft notes.

    The attackers then mapped clusters, fingerprinted the environment, checked for the Zimbra SSH identity, escalated privileges to root using legitimate Zimbra tools, and deployed a secondary persistence mechanism using a systemd service named zimlog.service.

    According to Microsoft, the hackers targeted Zimbra’s centralized service and authentication secrets for credential exfiltration, and used the login material for authenticated LDAP queries that allowed them to retrieve high-value secrets.

    They also used Zimbra’s existing SSH identity to access other nodes in the cluster, used HTTP and HTTPS callbacks to validate command execution, and deployed “a full remote-access agent providing interactive shell access, bidirectional file operations, and SOCKS5 proxying”.

    Zimbra Collaboration Suite users are advised to update their instances to version 10.1.20 or later, uninstall the optional package, disable the vulnerable configuration, restrict SNMP and SMTP access, and check their environments for potential compromise.

    Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack

    Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

    Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

    Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

    Disclosure Exploited Prior public Vulnerability wild Zimbra
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

    Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

    Alleged KillSec Ransomware Mastermind a 16-Year-Old

    ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

    How poor public transport policy is putting the brake on cities | Road transport

    Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Burnham wants to change British elections. Voters think they’re fine as is. – POLITICO

    October 2, 2026

    Whatever AI Safety Is, It’s Not This

    October 2, 2026

    A Coding Guide to Google Research’s Kauldron: Configs That Are Plain Data, Components Wired by String, and a JAX Trainer You Can Read End to End

    October 2, 2026

    Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

    October 2, 2026
    Latest Posts

    Max Miller Continues to Resist Pressure to Drop Out as Deadline Looms

    August 7, 2026

    Houthi attacks kill at least 10 in Yemen as rebels target oil-rich Marib

    August 8, 2026

    Scientists find unexpected life on Ötzi the Iceman’s 5,300-year-old body

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Burnham wants to change British elections. Voters think they’re fine as is. – POLITICO

    October 2, 2026

    Whatever AI Safety Is, It’s Not This

    October 2, 2026

    A Coding Guide to Google Research’s Kauldron: Configs That Are Plain Data, Components Wired by String, and a JAX Trainer You Can Read End to End

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.