Skip to content

Security1 publisher2 min readPublished

Some of the 50-plus Zimbra bugs Rapid7 found let attackers send mail as someone else without credentials

Rapid7's research with Zimbra turned up more than 50 vulnerabilities, several of which let an attacker send mail as another user with no password involved. The operational item today is CVE-2026-73570, the SNMP command injection CISA gave federal agencies three days to fix.

The Watch · Security desk

Photograph accompanying Some of the 50-plus Zimbra bugs Rapid7 found let attackers send mail as someone else without credentials
Photo: csoonline.com

What happened

  • Rapid7 says its collaborative research with Zimbra uncovered more than 50 vulnerabilities in the Zimbra Collaboration Suite, the first in a planned series of posts about the work.
  • Several of those bugs let an attacker impersonate a sender without credentials, control what a mailbox owner can see, and alter shared documents and calendars, according to Rapid7.
  • Rapid7 says meetings in the affected suite can be modified or deleted without generating the notification trail users expect to see.
  • Separately, CISA added CVE-2026-73570, an unauthenticated command injection through Zimbra's SNMP notification handling, to its exploited-vulnerability catalog on August 21 with a three-day federal deadline.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability A send that never authenticates gives credential-anomaly detection nothing to fire on, so the fraud surfaces when someone disputes a payment rather than when a login looks wrong.
  • constraint Responders who reconstruct BEC from mailbox artifacts lose their anchor if the attacker curates the Sent Items entry and the calendar change emits no event.
  • decision Zimbra operators can act on the catalogued SNMP bug now and can do nothing about the other 50 until Rapid7's later installments name them.
  • precedent On a platform with exploited bugs in five straight years, the reasonable planning assumption is that these findings get worked in the wild before most self-hosted instances are patched.

The familiar playbook is read-only: breach a mailbox, watch, map the approval chain, then divert a payment [3]. Rapid7's post runs a different sequence. Send as the CFO without touching the password, then choose what the CFO finds afterwards [2][4]. Delete the message and the trail goes with it. Leave it in Sent Items and the executive sees a record of a send they do not remember, while Finance holds a request that looks internal. Rapid7 describes an organization "trapped in a conflict of evidence" [5].

RSVP state is writable too, so a key executive can be moved from Accepted to Declined and leadership reads it as an opt-out [7]. Rapid7's author calls that "calendar warfare" [7]. On the documents side, the post describes planting a fake HR memo or financial summary in an executive's enterprise drive so it appears to come from a trusted peer, then following it days later with an email from another executive that references it, with neither artifact carrying the whole deception [8].

Rapid7 did not publish identifiers or patch status for the 50-plus bugs; the post says technical details and broader findings come in later installments of the series [9]. Nothing in it is patchable this week.

The exploited Zimbra bugs are current and separate. Shadowserver has been counting more than 260 compromised instances while hunting for exploitation artifacts of the SNMP command injection [11]. In October 2025, CISA added CVE-2025-27915, a stored XSS in the Classic Web Client that fires from a crafted .ICS attachment and was used as a zero-day against Brazilian military targets to steal mail and quietly set forwarding filters [12]. The delivery vehicle there was a calendar entry.

Proofpoint saw attackers exploiting CVE-2024-45519, unauthenticated command execution in the postjournal service, by stuffing base64 payloads into CC fields on September 28, 2024; CISA added it to the catalog five days later, on October 3 [13][16]. Rapid7 tracked widespread exploitation of CVE-2022-27925 and CVE-2022-37042 in 2022, a path traversal chained to an authentication bypass that dropped a JSP shell on a Zimbra server without credentials [14]. Google's Threat Analysis Group documented four separate threat groups working CVE-2023-37580 as a zero-day, each after mail, credentials and authentication tokens [15]. Counting both 2022 bugs, the post names six Zimbra CVEs with documented exploitation across five calendar years [17].

What to watch

  • The next installments in Rapid7's Zimbra series, which the post says will carry the technical details and broader findings.
  • Whether Zimbra ships fixes and identifiers for the 50-plus bugs, and whether any of them reach CISA's catalog.
  • Whether Shadowserver's count of compromised CVE-2026-73570 instances moves above 260.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories