Zimbra flaw CVE-2026-73570 was probed before disclosure and then exploited: update to 10.1.20 and check for intrusions
EditorialBy TrustList Editorial
Microsoft Threat Intelligence says the Zimbra command-injection flaw CVE-2026-73570, fixed on 20 July 2026, was probed from 28 July before its 13 August disclosure and later exploited. Servers with zimbra-snmp enabled need 10.1.20 and an intrusion check.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Email Management
- +1 more
About Zimbra flaw CVE-2026-73570 was probed before disclosure and then exploited: update to 10.1.20 and check for intrusions
Zimbra flaw CVE-2026-73570 was probed before disclosure and then exploited: update to 10.1.20 and check for intrusions
1 October 2026 — A command-injection flaw in the Zimbra Collaboration email server was being probed by attackers before it was publicly disclosed, and was then used to break into mail servers. Microsoft Threat Intelligence published its findings on 30 September 2026, and SecurityWeek and The Register reported them on 1 October.
Not yet independently verified. This rests on Microsoft’s research and the two reports of it; Zimbra’s own advisory was not read here, and the flaw was not in the US government’s exploited-flaws catalogue when checked on 30 September. We will update this when it can be confirmed, and remove this note.
What happened
According to Microsoft:
- CVE-2026-73570 is an unauthenticated command injection. It can be reached only on servers that have the optional zimbra-snmp package installed with SNMP notifications enabled.
- Zimbra 10.1.20, released on 20 July 2026, contains the fix. The flaw was publicly disclosed on 13 August 2026.
- Between 28 July and 7 August, after the fix shipped but before disclosure, Microsoft saw two scanning tools probing the vulnerable path, confirming that commands would run without yet delivering a payload.
- Exploitation followed, affecting organisations in more than one region and industry. Microsoft describes web shells and reverse shells, persistence as root, and mailbox archives being sent out to cloud storage.
The lesson is uncomfortable: the fix was available for more than three weeks before anyone was told why it mattered, and attackers appear to have worked that out from the patch.
Who is affected
Organisations that run their own Zimbra mail servers, and hosting and service providers that run them for customers, where zimbra-snmp is installed and SNMP notifications are on, and the server was not updated to 10.1.20 before the probing began. Our earlier item on the Zimbra 10.1.21 release covers a different set of flaws.
What to do
- Check the version on every Zimbra server and update to 10.1.20 or later; take the current release if you are updating anyway.
- Check whether zimbra-snmp is installed and SNMP notifications are enabled. If you do not need them, disable them.
- Hunt for signs of compromise from late July onwards: unfamiliar files in web directories, unexpected outbound connections and shells, new root-level persistence, and large mailbox exports. Microsoft's post lists the indicators it found.
- If you find any, treat it as a breach of email data, rotate credentials, and follow your incident and notification process.
- If a provider hosts your Zimbra, ask in writing when it applied 10.1.20 and whether it has checked for these indicators.
Sources
- Microsoft Threat Intelligence: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 — 30 September 2026
- SecurityWeek: Zimbra vulnerability exploited in the wild prior to public disclosure — 1 October 2026
- The Register: Microsoft catches hackers exploiting Zimbra bug before disclosure — 1 October 2026
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Email Management
- Threat Intelligence
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.