Active exploitation of Zimbra vulnerability allows attackers to deploy web shells and harvest corporate emails

Hackers are actively exploiting a critical vulnerability in Zimbra Collaboration Suite that permits unauthenticated remote command execution, enabling attackers to steal emails and authentication credentials from organizations. Microsoft detected two distinct scanning tools probing for vulnerable servers since late July, with attackers eventually deploying web shells and remote-access tools after successful exploitation. The vulnerability remains widespread, with approximately 10,000 Zimbra instances still vulnerable despite patches being available since July.
The vulnerability stems from improper handling of user input within the Zimbra SNMP notification system. When the optional zimbra-snmp package is installed and notifications are enabled, attackers can craft malicious SMTP requests that inject shell commands executed under the zimbra service account's privileges. Since the flaw requires no authentication, any internet-connected vulnerable server becomes an entry point for compromise.
Microsoft's investigation revealed a two-phase attack pattern. Initial reconnaissance probes validated successful exploitation across numerous targets between late July and early August. Once confirmed, threat actors deployed persistent tools including web shells and reverse shells, then systematically harvested email archives and credential information from compromised mail servers. The attacks affected multiple sectors and geographic regions, suggesting either opportunistic targeting or widespread coordinated activity.
Organizations using Zimbra Collaboration Suite face potential exposure of sensitive communications and authentication data if systems remain unpatched. The 10,000 estimated vulnerable instances suggest significant attack surface remains despite patch availability for months. Email compromise could enable secondary attacks through credential theft or facilitate espionage. However, the wide adoption of Zimbra primarily among mid-market and enterprise organizations may limit the total number of affected entities compared to consumer-facing platforms.