Zimbra CVE-2026-73570 exploited before public disclosure
Attackers began abusing a high-severity command injection flaw in Zimbra Collaboration Suite (ZCS) in the weeks after a fix was released but before the bug was publicly disclosed, according to Microsoft.
The vulnerability, tracked as CVE-2026-73570, carries a CVSS score of 8.9. It affects ZCS versions before 10.1.20 and allows unauthenticated attackers to run code remotely on vulnerable mail servers.
How the flaw works
The problem lies in how ZCS handles SNMP notifications. SNMP (Simple Network Management Protocol) is commonly used to monitor and manage network devices and services. In affected versions, untrusted input processed during these notifications is not properly sanitized, which opens the door to OS command injection.
Exploitation depends on two conditions: the optional zimbra-snmp package must be installed, and SNMP notifications must be enabled. If both are true, an attacker can trigger the bug by sending specially crafted SMTP requests, the protocol mail servers use to send and receive email.
A successful attack gives the intruder code execution with the privileges of the Zimbra user, without any need to log in first.
A gap between patch and disclosure
Zimbra shipped the fix on July 20 in ZCS 10.1.20. Public disclosure followed on August 13. On August 17, CERT Polska, Poland's national computer emergency response team, warned that the flaw was being exploited and published indicators of compromise (IoCs).
Microsoft's findings show the attacks started earlier than that.
"Between July 28 and August 7, after a fix became available on July 20 but before public disclosure on August 13, Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point," the company said.
This early reconnaissance did not deliver any payload. Instead, the probes were lightweight checks designed to confirm that commands could be executed through the vulnerable path. The same execution path was later used in actual exploitation.
From webshells to root
In the follow-up attacks, the intruders dropped JSP webshells into publicly reachable application directories. They also pulled and ran content using wget or curl, started background processes, and set up interactive reverse shells.
"Multiple JSP webshells were deployed across Jetty and mailboxd application paths, including additional copies on peer mailbox nodes. This provided alternative access paths across different Zimbra configurations and reduced reliance on a single webshell," Microsoft explained.
Once inside, the attackers:
- mapped the Zimbra clusters and fingerprinted the environment
- checked for the Zimbra SSH identity
- escalated privileges to root using legitimate Zimbra tools
- installed a secondary persistence mechanism as a systemd service called zimlog.service
The attackers were also after credentials. Microsoft says they went for Zimbra's centralized service and authentication secrets, then used the stolen login material to run authenticated LDAP queries that returned high-value secrets.
Zimbra's own SSH identity was used to move to other nodes in the cluster. HTTP and HTTPS callbacks confirmed that commands were running, and the attackers eventually deployed "a full remote-access agent providing interactive shell access, bidirectional file operations, and SOCKS5 proxying."
What admins should do
Organizations running ZCS are advised to:
- update to version 10.1.20 or later
- uninstall the optional zimbra-snmp package if it is not needed
- disable the vulnerable SNMP notification configuration
- restrict access to SNMP and SMTP
- check their environments for signs of compromise
Given that exploitation started before disclosure, patching alone may not be enough. Servers that were exposed between late July and the time the update was applied should be reviewed for webshells in Jetty and mailboxd paths, unexpected systemd services such as zimlog.service, and unusual use of the Zimbra SSH identity across cluster nodes.
Our Take
The most notable part of this case is the timeline. Attackers were probing the vulnerable code path about a week after the patch shipped and well before any public advisory. This suggests someone studied the fix closely, a practice often called patch diffing, and worked out the bug from the changes. For defenders, it is a reminder that a quiet release does not buy much time. The window between a fix and its weaponization appears to be shrinking, a trend that fits with the broader rise in vulnerability disclosures and faster exploitation we have been tracking.
Self-hosted webmail and collaboration platforms remain attractive targets. They sit on the internet, handle sensitive communications and store credentials that can unlock much more of a network. The post-exploitation activity here, from LDAP queries to lateral movement over SSH, shows the attackers were interested in far more than a single mailbox. It echoes the recent Roundcube SQL injection attacks, another case of mail software being pulled into active campaigns.
Microsoft has not attributed the activity to a specific group, and it is not clear how many organizations were hit. It is worth watching whether CERT Polska or other national teams share more victim data, and whether the IoCs connect this campaign to known actors. In the meantime, admins should treat any Zimbra server that was unpatched in late July as potentially compromised until proven otherwise, and review whether optional components like zimbra-snmp need to be installed at all.
