LiMP VPN
← All news

Zimbra Flaw Exploited by TargetZimbra Ransomware

Zimbra Flaw Exploited by TargetZimbra Ransomware

In short: A vulnerability tracked as CVE-2026-73570 in Zimbra Collaboration Suite lets an unauthenticated attacker run commands on the mail server through its SNMP notification component — all it takes is a specially crafted SMTP request sent to port 25, 465, or 587. A patch shipped back in July 2026 (version 10.1.20), but according to Russian security firm Positive Technologies (PT ESC IR) and an October vulnerability digest from R-Vision, the attacks haven't stopped: intruders drop JSP web shells and deploy a Go-based ransomware module called TargetZimbra, which encrypts files under /opt/zimbra/ with ChaCha20 and leaves a ransom note behind.

What happened

Zimbra Collaboration Suite is an open-source mail server companies run as an alternative to commercial platforms like Microsoft Exchange. The flaw sits in the optional zimbra-snmp package: when it's installed and SNMP notifications are enabled, the server mishandles part of the incoming data, and a crafted SMTP request forces it to run an arbitrary command as the zimbra system user. No password, no account, and no human action are required — just network access to the server. Before trusting mail and cloud services with sensitive data, it's worth knowing how secure your own VPN is in the first place — see our breakdown of what makes a VPN genuinely safe, with the same attention to encryption detail.

How the attack works

After exploiting CVE-2026-73570, attackers create a version.txt file in Zimbra's public web directory as a marker of successful compromise, then upload JSP web shells there to keep persistent remote access through an ordinary browser. From there, TargetZimbra takes over — a Go-based ransomware module that encrypts files under /opt/zimbra/ and its subdirectories with ChaCha20, appends the .elock extension to encrypted files, and drops a !README_RECOVER.txt ransom note in affected folders. Positive Technologies has tracked mass attacks following this pattern since mid-August 2026, and R-Vision listed CVE-2026-73570 among three September vulnerabilities already being exploited in real attacks — meaning the campaign didn't stop after disclosure and the patch shipped.

Why this matters beyond mail administrators

A company's mail server isn't just a piece of infrastructure: mailboxes hold correspondence with clients, employee personal data, financial documents, and passwords people routinely email to themselves out of habit. If ransomware reaches the Zimbra directory, a company loses access to its entire corporate mail at once, not just one file, and recovery can take days. For an everyday user, that means the risk of correspondence with a bank, employer, or clinic becoming either unavailable or stolen before encryption even happens — the web shells give attackers a chance to exfiltrate mailboxes first and detonate ransomware second.

How to protect yourself

If your organization runs Zimbra Collaboration Suite, upgrading to 10.1.20 or later is essential, and if SNMP notifications aren't needed for business reasons, disabling the zimbra-snmp package entirely is the safer call. It's also worth checking web application logs for stray JSP files and a version.txt file in the public directory — a sign that a compromise has already happened. There's no direct action required from an everyday user here, but it's one more reason not to store sensitive data in email and to use a dedicated encrypted vault for passwords instead of a mailbox.

This flaw sits on the mail provider's server side, so a regular consumer VPN doesn't close it directly. But the same principle holds for personal devices: the fewer unencrypted channels to your data, the lower the risk. The LiMP VPN app encrypts traffic between your device and LiMP VPN's servers under a no-logs policy, reducing the risk of interception along the way — regardless of what server software sits on the other end of the connection. Plans start at 69 ₽/month — details on the pricing page.

Sources