Thursday, October 1, 2026 Newsletter Advertise
Breaking
Cyber

Microsoft tracks Zimbra flaw CVE-2026-73570 exploited in the wild

Microsoft Threat Intelligence says attackers used a crafted email to run commands on internet-facing Zimbra servers, deploying web shells and stealing authentication keys.

Microsoft tracks Zimbra flaw CVE-2026-73570 exploited in the wild. CVE-2026-73570, Source: Microsoft

Microsoft Threat Intelligence said on September 30, 2026 that it identified and tracked exploitation of CVE-2026-73570, an unauthenticated operating-system command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. According to Microsoft, exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers without authentication or user interaction.

What the vulnerability is

Microsoft said an attacker can send a specially crafted SMTP request that introduces untrusted input into SNMP notification processing. If that input is not sufficiently sanitized, embedded shell commands can execute with the privileges of the zimbra service account.

Exploitation requires the optional zimbra-snmp package to be installed and SNMP notifications to be enabled, the company said. Microsoft said Zimbra version 10.1.20, released July 20, 2026, contains the relevant remediation, and that CVE-2026-73570 was publicly disclosed on August 13, 2026.

Microsoft telemetry identified activity targeting the same injection path during the interval between those two events. Between July 28 and August 7, the company said it observed two distinct out-of-band scanning tools probing the vulnerable injection point, using callbacks to collaborator services and HTTP requests carrying a ZB73570 User-Agent.

What attackers did after exploitation

Microsoft said observed post-exploitation activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution. Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed.

Multiple JSP web shells were deployed across Jetty and mailboxd application paths, including additional copies on peer mailbox nodes, the company said. In some cases attackers temporarily enabled write access to a public directory, deployed the web shell and then restored the directory permissions.

Microsoft described a privilege-escalation technique abusing Zimbra's sudo-authorized service helpers, in which the attacker replaced the zmmailboxd.out log with a symlink to the sudo PAM configuration, added a pam_exec session hook and created a NOPASSWD: ALL entry for the zimbra account. A second persistence mechanism used a systemd service named zimlog.service, installed outside Zimbra application directories and given timestamps matching existing units such as rsync.service and sshd.service.

The actor targeted centralized service and authentication secrets rather than individual mailbox passwords, Microsoft said, using zmlocalconfig -s and authenticated LDAP queries to retrieve attributes including zimbraPreAuthKey, zimbraAuthTokenKey and zimbraTwoFactorAuthSecret. Lateral movement used the existing SSH identity at /opt/zimbra/.ssh/zimbra_identity together with rsync to move payload fragments and web shells between cluster nodes.

Implants and an exfiltration attempt

Microsoft said one campaign used a multi-stage chain starting with a shell downloader called agent2.sh, which retrieved a stage 1 payload from a dynamic DNS domain. A Go binary named zimdown2 then installed the zimclient2 remote-access agent, which the company said provided interactive shell access, bidirectional file operations and SOCKS5 proxying over WebSocket, TLS and raw TCP transports.

A separate Go executable contained the embedded module path zimbra-exfil/client-dump and read /opt/zimbra/conf/localconfig.xml to extract service account credentials, Microsoft said. It then exported database tables including mailbox, mailbox_metadata, mobile_devices and out_of_office, staging the results in a timestamped directory under /tmp/ before compressing them into a ZIP archive for attempted transfer.

On one compromised server, the actor archived recent mailbox-backup content into /opt/zimbra/final.tar.gz, downloaded AzCopy and invoked it with an operator-supplied Azure Blob SAS URL. Microsoft said available evidence does not confirm that the transfer completed successfully.

Scope of the activity

Microsoft said it observed affected organizations in more than one region and industry, and that based on the environments investigated, exploitation was not limited to a single sector or geographic area. The activity included both automated payload delivery and hands-on-keyboard operations.

The company cautioned that its published attack chain combines behaviors observed across multiple confirmed compromises, and that no single host necessarily exhibited every stage. Microsoft also noted that Defender XDR advanced hunting retains 30 days of raw event data, which no longer covers the pre-disclosure reconnaissance described in the report.

What to do

  • Upgrade all Zimbra Collaboration Suite instances to version 10.1.20 or later, which Microsoft says remediates CVE-2026-73570.
  • If patching must wait, uninstall the optional zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts only.
  • Treat reverse-shell alerts on internet-facing mail servers as priority incidents; Microsoft says a confirmed reverse-shell connection indicates attacker access even when no payload is quarantined.
  • Do not rely solely on named-malware detections, since Microsoft says some of the most consequential outcomes involved only a plain interactive shell.
  • Rotate all domain zimbraPreAuthKey values and review systemd units for unexpected ownership, enablement or timestamp changes, including units that resemble Zimbra or operating-system logging components.
  • Inspect Zimbra application and servlet work directories on every mailbox node for unexpected JSP files, generated *_jsp.java or compiled servlet artifacts, and recent permission changes; do not assume removing one JSP eliminates access.
  • Where feasible, confine mail-server service accounts with namespace, seccomp or AppArmor controls to limit the impact of future command-injection flaws.
  • Enable Microsoft Defender for Endpoint protections on Linux servers, and hunt for the injection signature: a legitimate snmptrap invocation immediately followed by shell metacharacters and a wget or curl call wrapped in a trailing comment.
  • For activity older than the 30-day advanced hunting window, search second-stage infrastructure in Microsoft Sentinel or archived logs and pivot recovered indicators across the entire device fleet.
Key facts and where they come from
  • CVE-2026-73570 is an unauthenticated OS command injection flaw in Zimbra's SNMP notification path.
    CVE-2026-73570 is an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path.
  • Exploitation requires the optional zimbra-snmp package and enabled SNMP notifications, and needs no authentication or user interaction.
    Exploitation requires the optional zimbra-snmp package to be installed and SNMP notifications to be enabled.
  • Zimbra 10.1.20, released July 20, 2026, contains the fix; the CVE was disclosed August 13, 2026.
    Zimbra version 10.1.20, released July 20, 2026, contains the relevant remediation. CVE-2026-73570 was publicly disclosed on August 13, 2026.
  • Microsoft observed scanning of the injection point between July 28 and August 7, before public disclosure.
    Between July 28 and August 7, after a fix became available on July 20 but before public disclosure on August 13, Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point.
  • Post-exploitation activity included JSP web shells, reverse shells, privilege escalation and memory-backed execution.
    observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution
  • Attackers collected Zimbra authentication key material including zimbraPreAuthKey and zimbraAuthTokenKey.
    authenticated LDAP queries that retrieved high-value attributes, including zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret
  • A mailbox archive was staged as /opt/zimbra/final.tar.gz and an AzCopy transfer to Azure Blob was attempted, but completion is unconfirmed.
    available evidence does not confirm that the transfer completed successfully
  • Affected organizations spanned multiple regions and industries, Microsoft said.
    Microsoft observed affected organizations in more than one region and industry.

Read the original from Microsoft →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Cyber