Microsoft reported that threat actors exploited the patched Zimbra Collaboration Suite flaw CVE-2026-73570 to deploy web shells, gain persistence, and collect mailbox and authentication data across affected organizations. The activity also involved lateral movement, credential theft, and attempted exfiltration using tools such as Zimclient2 and AzCopy, prompting urgent patching and hardening guidance. #Zimbra #CVE-2026-73570 #CERTPolska #CISA #Zimclient2 #AzCopy
Keypoints
- Attackers weaponized CVE-2026-73570 in Zimbra Collaboration Suite.
- The flaw allowed unauthenticated command injection through specially crafted SMTP requests.
- Observed post-exploitation activity included JSP web shells, reverse shells, and persistence mechanisms.
- Threat actors stole mailbox data, authentication secrets, and other Zimbra configuration artifacts.
- Organizations were urged to patch immediately, disable SNMP features if needed, and hunt for web shell persistence.
Read More: https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html