Attackers actively exploit a critical Zimbra Collaboration Suite vulnerability to install web shells and extract authentication credentials from compromised mail servers. Microsoft Security Research documented campaigns leveraging CVE-2026-73570, an unauthenticated remote code execution flaw rated 8.9 on the CVSS severity scale.

The vulnerability resides in Zimbra's handling of Simple Network Management Protocol (SNMP) requests. Attackers send malicious SNMP queries that bypass authentication checks and inject arbitrary operating system commands. Because ZCS typically runs with elevated privileges on mail infrastructure, successful exploitation grants immediate system-level access. Threat actors use this foothold to deploy web shells, backdoors that persist across reboots and enable ongoing remote access.

The attack workflow follows a predictable pattern. Initial exploitation drops web shells into web-accessible directories on the Zimbra server. These shells become persistence mechanisms, allowing attackers to maintain access even after the original vulnerability closes. From the web shell, adversaries execute commands to harvest authentication tokens, session cookies, and plaintext credentials stored in Zimbra's mailbox databases. They then pivot to other systems using stolen credentials.

The threat actors' targeting extends beyond opportunistic scanning. Microsoft researchers observed focused campaigns against organizations in specific sectors, though the full scope remains under investigation. Zimbra Collaboration Suite powers mail infrastructure at enterprises, educational institutions, and government agencies. The platform's deployment depth means compromises ripple across entire organization networks.

Zimbra released patches addressing CVE-2026-73570, but adoption lags. Organizations running legacy versions or those with complex upgrade procedures remain exposed. The Common Vulnerabilities and Exposures record indicates the flaw affects multiple ZCS versions. Administrators must consult Zimbra's security advisories to confirm whether their deployments require patching.

Web shell deployment creates layers of exposure. First, attackers gain undetected mailbox access for weeks or months in some cases. Second, credential harvesting enables lateral movement to connected systems. Third, web shells survive patching unless administrators explicitly remove them. The persistence problem compounds the immediate access risk.

Organizations should prioritize three response actions. Immediately patch Zimbra to the latest fixed version if not already completed. Scan web-accessible directories for unfamiliar files, particularly in /opt/zimbra or publicly exposed paths. Review mail server logs from the past six months for suspicious SNMP traffic or web shell file creation events. If indicators surface, assume credential compromise and force password resets for users whose mailboxes the server hosted.

Threat hunters should monitor outbound connections from Zimbra servers to unfamiliar external IP addresses. Web shells typically beacon for commands or exfiltrate data over HTTP or HTTPS. Network detection systems should flag SNMP requests originating from untrusted networks or containing command injection patterns.

The exploitation of Zimbra infrastructure underscores how mail servers remain high-value targets. Email systems hold authentication tokens, calendar data, contact lists, and business communications. A compromised mail server becomes a beachhead for organizational infiltration. Defenders treating Zimbra deployments as perimeter infrastructure rather than internal systems often discover breaches too late.