Hackers Exploit Zimbra Mail Servers With Crafted Emails to Gain Remote Access
Attackers are exploiting Zimbra CVE-2026-73570 for unauthenticated command execution and credential theft on exposed mail servers.
Microsoft Threat Intelligence reported active exploitation of CVE-2026-73570, a command-injection flaw in Zimbra's optional SNMP notification feature. Crafted SMTP input reaches snmptrap and runs as the zimbra account with no login or user interaction. After reconnaissance from July 28 to August 7, operators planted JSP web shells, reverse shells, and a cryptominer, stole LDAP, MySQL, Postfix, and token-signing secrets, and moved laterally with existing SSH keys. Zimbra 10.1.20, released July 20 before public disclosure on August 13, fixes the issue.