September 30, 2026
Zimbra Flaw CVE-2026-73570 Exploited to Deploy Web Shells and Harvest Authentication Secrets Including PreAuth and 2FA Keys
Microsoft reported active exploitation of CVE-2026-73570 (CVSS 8.9), an unauthenticated OS command injection in Zimbra Collaboration triggerable via a crafted SMTP request when zimbra-snmp and SNMP notifications are present. Attackers deployed JSP web shells and reverse shells, escalated privileges via /etc/pam.d/sudo, and used zmlocalconfig plus LDAP queries to steal zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret, then exfiltrated mailbox archives using AzCopy to attacker cloud storage.
Harvesting pre-auth and token signing keys lets attackers mint valid sessions against mail APIs indefinitely, so patching alone is insufficient. Secret rotation plus monitoring for anomalous authenticated API access is required.