Skip to content
TrustList
News

Zimbra flaw CVE-2026-73570 was probed before disclosure and then exploited: update to 10.1.20 and check for intrusions

Editorial

By TrustList Editorial

Microsoft Threat Intelligence says the Zimbra command-injection flaw CVE-2026-73570, fixed on 20 July 2026, was probed from 28 July before its 13 August disclosure and later exploited. Servers with zimbra-snmp enabled need 10.1.20 and an intrusion check.

About Zimbra flaw CVE-2026-73570 was probed before disclosure and then exploited: update to 10.1.20 and check for intrusions

Zimbra flaw CVE-2026-73570 was probed before disclosure and then exploited: update to 10.1.20 and check for intrusions

1 October 2026 — A command-injection flaw in the Zimbra Collaboration email server was being probed by attackers before it was publicly disclosed, and was then used to break into mail servers. Microsoft Threat Intelligence published its findings on 30 September 2026, and SecurityWeek and The Register reported them on 1 October.

Not yet independently verified. This rests on Microsoft’s research and the two reports of it; Zimbra’s own advisory was not read here, and the flaw was not in the US government’s exploited-flaws catalogue when checked on 30 September. We will update this when it can be confirmed, and remove this note.

What happened

According to Microsoft:

  • CVE-2026-73570 is an unauthenticated command injection. It can be reached only on servers that have the optional zimbra-snmp package installed with SNMP notifications enabled.
  • Zimbra 10.1.20, released on 20 July 2026, contains the fix. The flaw was publicly disclosed on 13 August 2026.
  • Between 28 July and 7 August, after the fix shipped but before disclosure, Microsoft saw two scanning tools probing the vulnerable path, confirming that commands would run without yet delivering a payload.
  • Exploitation followed, affecting organisations in more than one region and industry. Microsoft describes web shells and reverse shells, persistence as root, and mailbox archives being sent out to cloud storage.

The lesson is uncomfortable: the fix was available for more than three weeks before anyone was told why it mattered, and attackers appear to have worked that out from the patch.

Who is affected

Organisations that run their own Zimbra mail servers, and hosting and service providers that run them for customers, where zimbra-snmp is installed and SNMP notifications are on, and the server was not updated to 10.1.20 before the probing began. Our earlier item on the Zimbra 10.1.21 release covers a different set of flaws.

What to do

  • Check the version on every Zimbra server and update to 10.1.20 or later; take the current release if you are updating anyway.
  • Check whether zimbra-snmp is installed and SNMP notifications are enabled. If you do not need them, disable them.
  • Hunt for signs of compromise from late July onwards: unfamiliar files in web directories, unexpected outbound connections and shells, new root-level persistence, and large mailbox exports. Microsoft's post lists the indicators it found.
  • If you find any, treat it as a breach of email data, rotate credentials, and follow your incident and notification process.
  • If a provider hosts your Zimbra, ask in writing when it applied 10.1.20 and whether it has checked for these indicators.

Sources

Categories & features