Attackers have been exploiting critical Zimbra flaw to steal emails

Attackers have been exploiting critical Zimbra flaw to steal emails

攻击者利用 Zimbra 关键漏洞窃取电子邮件

Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organizations, Microsoft has warned. The vulnerability, tracked as CVE-2026-73570, lets attackers remotely issue operating system commands without authentication. 微软警告称,黑客一直在利用 Zimbra Collaboration Suite 中的一个关键漏洞,试图获取受影响组织的电子邮件备份和身份验证凭据。该漏洞被追踪为 CVE-2026-73570,允许攻击者在未经身份验证的情况下远程执行操作系统命令。

Zimbra maintainer Synacor issued a patch on July 20, but didn’t disclose the vulnerability for more than three weeks after that. The security-focused Shadowserver Foundation said last week that its scans found that 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks following that. Currently, Shadowserver is tracking about 10,000 instances. Zimbra 的维护者 Synacor 于 7 月 20 日发布了补丁,但在随后的三周多时间里并未披露该漏洞。专注于安全的 Shadowserver 基金会上周表示,其扫描发现有 274 个独立的 Zimbra Collaboration Suite 实例已被入侵。运行该软件的服务器数量从补丁发布后一周的 19,000 台波动至随后的约 12,000 台。目前,Shadowserver 正在追踪约 10,000 个实例。

Look, ma, no authorization: From July 28 to August 7, Microsoft said Wednesday, the company detected two distinct scanning tools probing the Internet for vulnerable endpoints. The attackers first validated their exploit worked by sending HTTP requests and DNS, ICMP, and out-of-band identity checks to domains hosted on public services. The probes allowed the attackers to confirm the exploit successfully executed commands on vulnerable servers without actually compromising them. 看,妈,无需授权:微软周三表示,从 7 月 28 日到 8 月 7 日,该公司检测到两种不同的扫描工具在互联网上探测易受攻击的端点。攻击者首先通过向托管在公共服务上的域名发送 HTTP 请求以及 DNS、ICMP 和带外身份检查,来验证其漏洞利用程序是否有效。这些探测使攻击者能够在不实际入侵的情况下,确认漏洞利用程序已在易受攻击的服务器上成功执行了命令。

Eventually, the attackers began using their command injection capability to install malicious payloads. Microsoft wrote: Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution. Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed. The activity included both automated payload delivery and hands-on-keyboard operations on compromised mail servers. 最终,攻击者开始利用其命令注入能力安装恶意负载。微软写道:在成功利用漏洞后,观察到的活动包括部署 JSP Web Shell 和反向 Shell、权限提升、持久化远程访问工具以及基于内存的执行。威胁行为者还访问了电子邮件并收集了身份验证和邮箱数据,并观察到了创建归档文件及随后的传输活动。这些活动既包括自动化的负载投递,也包括在受损邮件服务器上进行的“键盘操作”(人工操作)。

Microsoft observed affected organizations in more than one region and industry. Based on the environments investigated, exploitation was not limited to a single sector or geographic area. 微软观察到受影响的组织分布在多个地区和行业。根据调查的环境来看,漏洞利用并不局限于单一行业或地理区域。

CVE-2026-73570 allows remote attackers with no credentials to run operating system commands through a crafted email that targets the ZCS SNMP notification path but only when an optional zimbra-snmp package is in place and SNMP notifications are enabled. “An attacker can send a specially crafted SMTP request that introduces untrusted input into SNMP notification processing,” Microsoft explained. “If the input is not sufficiently sanitized, embedded shell commands can execute with the privileges of the zimbra service account.” CVE-2026-73570 允许没有凭据的远程攻击者通过针对 ZCS SNMP 通知路径的精心构造的电子邮件来运行操作系统命令,但这仅在安装了可选的 zimbra-snmp 包且启用了 SNMP 通知时才有效。微软解释说:“攻击者可以发送一个特制的 SMTP 请求,将不受信任的输入引入 SNMP 通知处理过程中。如果输入未经过充分清理,嵌入的 Shell 命令就可以以 zimbra 服务账户的权限执行。”

Microsoft said the attackers it observed went on to install the webshells and use them to issue commands to create email backups and collect credentials. The company said it had no means to verify that the attackers successfully exfiltrated that data. Microsoft provided no details about who the attackers were or whether they were nation-state actors or financially motivated criminals. 微软表示,其观察到的攻击者随后安装了 Web Shell,并利用它们发出命令来创建电子邮件备份并收集凭据。该公司表示,无法核实攻击者是否成功窃取了这些数据。微软没有提供关于攻击者身份的详细信息,也没有说明他们是国家级黑客还是出于经济动机的犯罪分子。

Anyone responsible for maintaining ZCS software should ensure they’re running version 10.1.20 or later. The company provides other guidance for locking down systems. 任何负责维护 ZCS 软件的人员都应确保其运行的是 10.1.20 或更高版本。该公司还提供了其他用于锁定系统的指导建议。