Italy's CSIRT finds Zimbra servers hit by ransomware and miners
EditorialBy TrustList Editorial
Most intrusions trace to CVE-2026-73570 on servers with the optional SNMP package. In one case more than 6,000 mailboxes were down for 48 hours, and patched servers were not breached.
- Italy
- Cybersecurity
- Vulnerability Management
- Patch Management
About Italy's CSIRT finds Zimbra servers hit by ransomware and miners
Italy's CSIRT finds Zimbra servers hit by ransomware and miners
5 October 2026: Italy's national CSIRT says it has seen multiple compromises of internet-facing Zimbra Collaboration Suite servers, most of them through CVE-2026-73570, a command-injection flaw reachable when the optional zimbra-snmp package is installed. It reports no successful intrusions on instances that were kept up to date.
Not yet independently verified. Single source: the Italian CSIRT bulletin, whose counts come from incidents notified to it. We will add independent confirmation when we find it. We will update this when it can be confirmed, and remove this note.
The bulletin, numbered BL01/261005/CSIRT-ITA, describes remote code execution as the zimbra application user, followed by webshells and scheduled tasks to keep access. The outcomes differ from site to site. Two incidents ended in ransomware, one on a Zimbra 8.7.11 instance and one in which an executable tied to the ELock family was dropped. Three involved cryptominers, including a server on 10.1.19 that had not received the 10.1.20 patch the vendor shipped in July 2026. Others lost the LDAP database and credential hashes, had every mailbox password reset by the intruder, or were turned into a base for SSH brute-forcing against third parties.
The worst reported case was a mail outage of 48 hours that affected more than 6,000 user mailboxes, with webshells named Cykrrva8.jsp, Xv03ug6v.jsp, Config.jsp, info.jsp and rr.jsp found in the web directory. Two of the webshell cases shared five command-and-control addresses, which the CSIRT says may mean one campaign but cannot prove.
Older flaws were also in play: CVE-2024-45519, CVE-2022-41352, CVE-2022-27925, CVE-2022-37042 and CVE-2023-38750 each appear in at least one incident. One server that was formally being decommissioned but still exposed lost all its mailbox passwords through an unidentified route.
The CSIRT lists as affected any release before 10.1.20 with zimbra-snmp installed and SNMP notifications enabled, plus unpatched older branches: 10.1.x before 10.1.1, 10.x.x before 10.0.9, 9.x.x before Patch 41 and anything before 8.8.15 Patch 41.
If patching cannot happen at once, it advises disabling or removing zimbra-snmp, which takes away the prerequisite for the injection. It also asks administrators to check the zimbra user's crontab (crontab -u zimbra -l) and /opt/zimbra/.ssh/authorized_keys, and to look for stray JSP files under /opt/zimbra/jetty_base/webapps/zimbra/public/ and for payloads in /tmp and /var/tmp. Where a webshell turns up, it recommends rotating every mailbox and admin credential, since the stolen LDAP data would otherwise stay useful.
Two network measures are on its list as well: keep the admin port TCP 7071 off the public internet, and filter outbound traffic from mail servers so that IRC and odd ports such as TCP 8801 cannot reach a command server.
Company profile on TrustList: Zimbra
Sources
Categories & features
- Italy
- Cybersecurity
- Vulnerability Management
- Patch Management
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More ItalyThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.