Skip to content
TrustList
News

Italy's CSIRT finds Zimbra servers hit by ransomware and miners

Editorial

By TrustList Editorial

Most intrusions trace to CVE-2026-73570 on servers with the optional SNMP package. In one case more than 6,000 mailboxes were down for 48 hours, and patched servers were not breached.

About Italy's CSIRT finds Zimbra servers hit by ransomware and miners

Italy's CSIRT finds Zimbra servers hit by ransomware and miners

5 October 2026: Italy's national CSIRT says it has seen multiple compromises of internet-facing Zimbra Collaboration Suite servers, most of them through CVE-2026-73570, a command-injection flaw reachable when the optional zimbra-snmp package is installed. It reports no successful intrusions on instances that were kept up to date.

Not yet independently verified. Single source: the Italian CSIRT bulletin, whose counts come from incidents notified to it. We will add independent confirmation when we find it. We will update this when it can be confirmed, and remove this note.

The bulletin, numbered BL01/261005/CSIRT-ITA, describes remote code execution as the zimbra application user, followed by webshells and scheduled tasks to keep access. The outcomes differ from site to site. Two incidents ended in ransomware, one on a Zimbra 8.7.11 instance and one in which an executable tied to the ELock family was dropped. Three involved cryptominers, including a server on 10.1.19 that had not received the 10.1.20 patch the vendor shipped in July 2026. Others lost the LDAP database and credential hashes, had every mailbox password reset by the intruder, or were turned into a base for SSH brute-forcing against third parties.

The worst reported case was a mail outage of 48 hours that affected more than 6,000 user mailboxes, with webshells named Cykrrva8.jsp, Xv03ug6v.jsp, Config.jsp, info.jsp and rr.jsp found in the web directory. Two of the webshell cases shared five command-and-control addresses, which the CSIRT says may mean one campaign but cannot prove.

Older flaws were also in play: CVE-2024-45519, CVE-2022-41352, CVE-2022-27925, CVE-2022-37042 and CVE-2023-38750 each appear in at least one incident. One server that was formally being decommissioned but still exposed lost all its mailbox passwords through an unidentified route.

The CSIRT lists as affected any release before 10.1.20 with zimbra-snmp installed and SNMP notifications enabled, plus unpatched older branches: 10.1.x before 10.1.1, 10.x.x before 10.0.9, 9.x.x before Patch 41 and anything before 8.8.15 Patch 41.

If patching cannot happen at once, it advises disabling or removing zimbra-snmp, which takes away the prerequisite for the injection. It also asks administrators to check the zimbra user's crontab (crontab -u zimbra -l) and /opt/zimbra/.ssh/authorized_keys, and to look for stray JSP files under /opt/zimbra/jetty_base/webapps/zimbra/public/ and for payloads in /tmp and /var/tmp. Where a webshell turns up, it recommends rotating every mailbox and admin credential, since the stolen LDAP data would otherwise stay useful.

Two network measures are on its list as well: keep the admin port TCP 7071 off the public internet, and filter outbound traffic from mail servers so that IRC and odd ports such as TCP 8801 cannot reach a command server.

Company profile on TrustList: Zimbra

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy