// AI threat desk · 2 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesCriticalCVECVSS 8.9

Zimbra Flaw CVE-2026-73570 Exploited Before Public Disclosure, Microsoft Finds

Microsoft’s threat intelligence team says attackers exploited Zimbra Collaboration Suite flaw CVE-2026-73570 (CVSS 8.9) before it was publicly disclosed, planting web shells and stealing mailboxes and authentication keys across servers in multiple regions and industries.

Illustration: server room racks, symbolizing enterprise mail server infrastructure.
File photo: Illustration: server room racks, symbolizing enterprise mail server infrastructure.. Photo: rawpixel (CC0)
Key takeaways
  • CVE-2026-73570 is an unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite, with a CVSS score of 8.9. It can be triggered by a crafted email without authentication or user interaction.
  • Microsoft found that attackers began scanning and probing the exploitation path as early as between Jul 28 and Aug 7, after the patch was released but before the flaw was publicly disclosed.
  • After gaining access, attackers planted JSP web shells, escalated privileges to root, built multiple persistence mechanisms, and targeted Zimbra’s centralized authentication keys, such as zimbraPreAuthKey, for theft.
On this page

Flaw lets unauthenticated attackers run remote commands

According to Microsoft’s security research team report, CVE-2026-73570 exists in how Zimbra Collaboration Suite handles SNMP notifications. When the zimbra-snmp package is installed and SNMP notifications are enabled, attackers can inject unfiltered input into the snmptrap command triggered by swatchdog, using a crafted SMTP request (an email). This lets them run arbitrary commands with zimbra service account privileges, without authentication or user interaction.

Zimbra released version 10.1.20 on Jul 20, 2026 to fix the flaw. But the vulnerability was not publicly disclosed until Aug 13 that year. Microsoft’s telemetry shows the attack activity took place in the window between the patch release and the public disclosure.

Attackers scanned and ran full attack chains before disclosure

Microsoft says that between Jul 28 and Aug 7, two different out-of-band scanning tools probed the injection path. They used commands like curl, wget, ping, nslookup and id to verify command execution, but did not deploy follow-up payloads. The goal was only to confirm the flaw could be exploited.

After successful exploitation, attackers planted multiple JSP web shells in the Jetty and mailboxd application paths, maintaining persistence through cron, systemd or memfd_create. They also used Zimbra’s own admin tools to modify the /etc/pam.d/sudo configuration file, granting the zimbra service account passwordless sudo privileges and root access. Microsoft also found attackers creating a systemd service named zimlog.service as a second persistence method.

According to SecurityWeek, citing Microsoft’s report, Poland’s CERT Polska was the first to publicly flag signs of exploitation on Aug 17, 2026, and released indicators of compromise (IoCs). It advised administrators to check /var/log/zimbra.log and Zimbra’s webapps directory for abnormal files.

Attackers targeted centralized authentication keys and mailbox backups

Microsoft’s report says attackers did not steal individual user passwords one by one. Instead, they used the zmlocalconfig -s command to obtain the centralized credentials Zimbra uses for LDAP, MySQL, Postfix and Amavis. They then used these credentials to run authenticated LDAP queries and obtain high-value keys, including zimbraPreAuthKey, zimbraAuthTokenKey and zimbraTwoFactorAuthSecret.

Attackers also used Zimbra’s existing SSH identity credentials to move laterally between other trusted nodes in the cluster, transferring web shells and auxiliary scripts via rsync. Some attack chains deployed a remote access tool named Zimclient2, which supports WebSocket, TLS and raw TCP transport, providing interactive shell access, two-way file operations and SOCKS5 proxy functions. On one compromised server, attackers compressed mailbox backup content into final.tar.gz, then downloaded Microsoft’s official AzCopy tool, attempting to exfiltrate the data via an operator-supplied Azure Blob SAS URL. Current evidence does not confirm whether the transfer was completed.

US cybersecurity agency adds flaw to known exploited list

According to The Hacker News, the US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to complete patching by Aug 24, 2026. Microsoft says affected organizations span more than one region and industry, but the identity of the attackers behind the campaign has not been determined. Not every victim host showed every stage of the attack chain.

What to do now

  1. Upgrade Zimbra Collaboration Suite to version 10.1.20 or later immediately.
  2. If immediate patching is not possible, uninstall the zimbra-snmp package and disable SNMP notifications. Restrict SNMP and SMTP connections to trusted hosts only.
  3. Rotate Zimbra’s authentication keys and service account credentials, including zimbraPreAuthKey and zimbraAuthTokenKey.
  4. Check the Jetty and mailboxd application directories and scan for leftover web shell persistence traces.
  5. Review the /etc/pam.d/sudo configuration file and the systemd service list for suspicious persistence entries such as zimlog.service.
  6. Review /var/log/zimbra.log for records of abnormal Zimbra service restarts.

FAQ

What is the CVE-2026-73570 vulnerability?

It is an unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite, with a CVSS score of 8.9. Attackers can run remote commands without authentication through a crafted email, when SNMP notifications are enabled.

Has this flaw already been used in real attacks?

Yes. Microsoft’s telemetry shows attackers began scanning and probing the flaw as early as between Jul 28 and Aug 7, 2026, after the patch was released but before public disclosure, and later carried out full attack chains including planting web shells.

How can I tell if my Zimbra server is affected?

If your Zimbra Collaboration Suite version is earlier than 10.1.20, and the zimbra-snmp package is installed with SNMP notifications enabled, your server is affected. Upgrade immediately, or uninstall the package and disable the feature if an upgrade is not possible.

What do attackers do after gaining access?

According to Microsoft’s report, attackers plant JSP web shells, escalate privileges to root, build multiple persistence mechanisms, and steal Zimbra’s centralized authentication keys and mailbox data. In some cases, they tried to exfiltrate compressed files using cloud storage tools.

Which organization or hacker group carried out this attack?

Microsoft says the identity of the attackers has not been determined. The report does not attribute the activity to any named group.

Sources

  1. Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570, MicrosoftPrimary
Explore with AI