News Windows

CVE-2026-73570: Unauthenticated command injection puts internet-facing Zimbra servers at risk

CVE-2026-73570 Zimbra vulnerability

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated operating-system command-injection vulnerability in the Zimbra Collaboration Suite. The issue affects a specific configuration: the optional zimbra-snmp package must be installed and SNMP notifications must be enabled on an internet-facing Zimbra server.

According to Microsoft Threat Intelligence, an attacker can send a specially crafted SMTP request that reaches Zimbra’s SNMP notification path. Unsanitized input can then allow shell commands to run with the privileges of the zimbra service account. No authentication or user interaction is required.

Microsoft says it observed activity targeting the injection path before the vulnerability was publicly disclosed. A fix became available with Zimbra version 10.1.20, released on July 20, 2026, while public disclosure followed on August 13. The report does not establish that every Zimbra deployment is affected; exposure depends on the package and notification settings described above.

What Microsoft observed after exploitation

The activity investigated by Microsoft went beyond basic command execution. Confirmed compromises included JSP web shells, reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution. The attackers also accessed email and collected authentication and mailbox data. In some cases, they created archives before transferring data from compromised mail servers.

The reported activity combined automated payload delivery with hands-on-keyboard operations. Microsoft observed affected organizations in more than one region and industry, so the activity was not limited to a single sector or geography. Microsoft also cautions that its attack-chain diagram combines behavior from multiple confirmed compromises; an individual host did not necessarily show every stage.

A separate Neowin report summarizes the same Microsoft warning and highlights the risk of session-token theft and persistent webshell installation.

What administrators should check

Administrators responsible for internet-facing Zimbra systems should first determine whether the optional zimbra-snmp package is installed and whether SNMP notifications are enabled. They should also verify that affected systems are running Zimbra version 10.1.20 or a later release, where available. The evidence provided here does not specify a later version number or give configuration-specific instructions for disabling the feature, so teams should use Zimbra’s official maintenance guidance for their deployment.

Systems that match the affected configuration deserve particular scrutiny because exploitation does not require valid credentials. Review available mail-server, authentication, and host telemetry for signs of unexpected command execution, web-shell activity, reverse-shell connections, persistent access tools, or unusual archive and data-transfer activity. Microsoft’s report describes detection opportunities, but the available material does not include a complete indicator list or detection rule set.

If compromise is suspected, treat the mail server and its stored data as potentially exposed. Investigate authentication and mailbox access, review session activity, and preserve relevant evidence before making changes that could remove useful forensic information. The precise response should follow the organization’s incident-response process and Zimbra’s official guidance.

CVE-2026-73570 matters because it combines an unauthenticated entry point with a mail-server role that can expose communications, credentials, and access tokens. The immediate operational question is not whether every Zimbra installation is vulnerable, but whether an internet-facing deployment has the required SNMP components and settings—and whether it has been updated to the release containing the remediation.

Stay Updated with ToolsLib! 🚀
Join our community to receive the latest cybersecurity tips, software updates, and exclusive insights straight to your inbox!

Discover more from ToolsLib Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading

×