Attackers began exploiting a critical flaw in the Zimbra Collaboration Suite weeks before the bug was publicly disclosed, according to Microsoft Threat Intelligence, turning exposed mail servers into launchpads for credential theft and mailbox raids.[1][3][11]
In a report published at the end of September, Microsoft said it had tracked real-world use of CVE-2026-73570 against internet-facing Zimbra instances between late July and early August, preceding formal disclosure and amplifying the risk for unpatched organizations.[1][3][15]
CVE-2026-73570 is an unauthenticated operating system command injection vulnerability in Zimbra’s optional SNMP notification component that allows remote code execution when the zimbra-snmp package is installed and SNMP notifications are enabled.[1][2][8]
An attacker can trigger the flaw by sending a specially crafted email to a vulnerable, internet-facing server, causing improperly sanitized input to flow into shell commands executed with the privileges of the Zimbra service account.[1][2][9]
The bug has been assigned a CVSS v3.1 base score of 8.9, reflecting its combination of ease of exploitation, lack of authentication requirements, and potential impact on confidentiality and integrity.[6][11][14]
Synacor patched the issue in Zimbra Collaboration 10.1.20, released on July 20, 2026, but wider public awareness followed weeks later as vulnerability databases, security advisories and government alerts documented the flaw and its active exploitation.[1][2][4]
Security advisories from multiple national CERTs note that all ZCS versions prior to 10.1.20 are affected when the SNMP component is present, and some warn that CVE-2026-73570 has already been added to known exploited vulnerability catalogs.[8][14][15]
Microsoft observed at least two separate scanning tools probing Zimbra’s SNMP notification path between July 28 and August 7, initially focused on identifying vulnerable servers and confirming command execution by making systems call back to attacker-controlled infrastructure.[1][3]
Once they found targets, the intruders deployed web shells and reverse shells, escalated privileges, installed tooling for persistent remote access, and ran malicious code directly in memory to reduce forensic artifacts.[1][3][11]
In some cases, attackers temporarily modified permissions on public directories to plant web shells before restoring the original settings, a deliberate attempt to hide their tracks while retaining backdoor access.[1][3]
Investigators also saw the attackers enumerate other Zimbra mail servers in the same environment, abusing existing SSH trust relationships to move laterally and, on at least one host, elevate their foothold to root and configure passwordless persistence for future commands.[1][3][11]
Beyond system access, the campaign heavily targeted email data, with Microsoft reporting that the attackers searched for Zimbra credentials and authentication secrets that could unlock user mailboxes.[1][3]
One custom tool recovered in the intrusions was designed to scrape service account credentials and extract mailbox information directly from Zimbra databases, underscoring the emphasis on intelligence collection.[1][11]
In another incident, the attackers bundled recent mailbox backups into an archive and attempted to exfiltrate the trove to Azure Blob Storage using the legitimate AzCopy utility, though investigators could not confirm whether the transfer succeeded.[1][3]
The activity affected organizations across multiple regions and sectors, ranging from largely automated exploitation to hands-on-keyboard operations, but Microsoft has not publicly attributed the attacks to a specific threat group.[1][3][12]
Administrators running Zimbra Collaboration versions earlier than 10.1.20 are urged to update as soon as possible, since patching fully removes the vulnerable SNMP notification code path.[2][5][13]
For environments where immediate upgrades are not feasible, vendor and government advisories recommend uninstalling the optional zimbra-snmp package or disabling SNMP notifications to effectively eliminate the attack surface.[5][8][14]
Given that CVE-2026-73570 is under active exploitation and listed in known exploited vulnerability databases, organizations should also hunt for signs of compromise such as unexpected outbound callbacks, newly created or obfuscated web shells, anomalous mailbox access and suspicious use of tools like AzCopy from mail servers.[8][11][15]
References
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 | Microsoft Security Blog
- Home – NVD – NIST
- Microsoft catches hackers exploiting Zimbra bug before disclosure
- CVE-2026-73570 – GitHub Advisory Database
- CVE-2026-73570 – Vulnerability Details – OpenCVE
- Zimbra SNMP Flaw Under Active Exploitation (CVE-2026-73570)
- High-Severity Vulnerability in Zimbra Collaboration Suite
- Zimbra Mail Servers Under Siege: How One Crafted Email Unlocked Mass Credential Theft
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and …
- CVE-2026-73570: Exploited Zimbra Command Injection Requires Patch and Persistence Hunt
- Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
- Zimbra Multiple Vulnerabilities
- Zimbra security advisory (AV26-816) β Update 1
