MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-30 · via Ars Technica

Active exploitation of Zimbra vulnerability allows attackers to deploy web shells and harvest corporate emails

Image via Ars Technica
Image via Ars Technica

Hackers are actively exploiting a critical vulnerability in Zimbra Collaboration Suite that permits unauthenticated remote command execution, enabling attackers to steal emails and authentication credentials from organizations. Microsoft detected two distinct scanning tools probing for vulnerable servers since late July, with attackers eventually deploying web shells and remote-access tools after successful exploitation. The vulnerability remains widespread, with approximately 10,000 Zimbra instances still vulnerable despite patches being available since July.

Expanded Detail

The vulnerability stems from improper handling of user input within the Zimbra SNMP notification system. When the optional zimbra-snmp package is installed and notifications are enabled, attackers can craft malicious SMTP requests that inject shell commands executed under the zimbra service account's privileges. Since the flaw requires no authentication, any internet-connected vulnerable server becomes an entry point for compromise.

Microsoft's investigation revealed a two-phase attack pattern. Initial reconnaissance probes validated successful exploitation across numerous targets between late July and early August. Once confirmed, threat actors deployed persistent tools including web shells and reverse shells, then systematically harvested email archives and credential information from compromised mail servers. The attacks affected multiple sectors and geographic regions, suggesting either opportunistic targeting or widespread coordinated activity.

Context

Organizations using Zimbra Collaboration Suite face potential exposure of sensitive communications and authentication data if systems remain unpatched. The 10,000 estimated vulnerable instances suggest significant attack surface remains despite patch availability for months. Email compromise could enable secondary attacks through credential theft or facilitate espionage. However, the wide adoption of Zimbra primarily among mid-market and enterprise organizations may limit the total number of affected entities compared to consumer-facing platforms.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Ars Technica →
Related stories
Critical Zimbra Vulnerability Allows Unauthorized Remote Code Execution and Data Theft · Cybersecurity
State-Sponsored Actors Exploited NetScaler Vulnerability to Target Dozens of Organizations Across North America and Europe · Cybersecurity
Cisco SD-WAN Manager Zero-Day Allows Admin-Level API Access Without Credentials · Cybersecurity
OpenInfra Foundation Warns of Compromised Software Repository Following Exploitation of Unpatched Authentication Bypass Flaw · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Attackers have been exploiting critical Zimbra flaw to steal emails.” Browse more stories.