Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Summary

Threat actors are actively exploiting a patched vulnerability in Zimbra Collaboration Suite (ZCS) to deploy web shells and steal authentication secrets. The attack leverages CVE-2026-73570, an unauthenticated OS command injection flaw that allows for remote code execution.

IFF Assessment

FOE

This article details an active exploit of a vulnerability, posing a direct threat to organizations using Zimbra Collaboration Suite.

Severity

8.9 High

CISA KEV: Listed as actively exploited. Federal patch due: August 24, 2026. Known ransomware use: Unknown.

Defender Context

Organizations using Zimbra Collaboration Suite should ensure they have applied the necessary patches to mitigate the risk of exploitation for CVE-2026-73570. Defenders should monitor for signs of web shell deployment and unauthorized access to mailbox data, as this vulnerability allows for remote code execution and harvesting of authentication secrets.

Read Full Story →