Microsoft catches hackers exploiting Zimbra bug before disclosure
Attackers exploited Zimbra CVE-2026-73570 before disclosure to plant shells, steal mail, and move laterally.
Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570, an unauthenticated command injection in Zimbra Collaboration Suite, weeks before its August 13 public disclosure. A crafted email can run commands on internet-facing servers that have Zimbra's optional SNMP monitoring package with notifications enabled. After the July 20 fix in version 10.1.20, Microsoft saw scanning from July 28 to August 7, followed by web shells, reverse shells, privilege escalation to root, credential theft, mailbox collection, and an attempted AzCopy transfer to Azure Blob Storage. Activity hit organizations in multiple regions and industries and is not attributed to a named group.
- CVE-2026-73570 is an unauthenticated command injection in Zimbra Collaboration.
- Zimbra fixed it in 10.1.20 on July 20; public disclosure was August 13.
- Microsoft observed probing from July 28, before the CVE was published.
- Attackers deployed shells, stole mailbox secrets, and tried AzCopy exfiltration.
- Only servers with optional SNMP notifications enabled are vulnerable.
Vulnerabilities mentionedAll →
- CVE-2026-735708.972%Unauthenticated OS Command Injection RCE in Synacor Zimbra Collaboration Suitepublished · Synacor Zimbra Collaboration Suite (ZCS) KEV PoC ×5
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article531 words · extracted from theregister.com · click to collapse
security
Attackers were probing the mail server flaw weeks before it had a CVE to its name
Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems.
Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers.
No stolen password or unfortunate employee clicking a dodgy link is required. An attacker can send a specially crafted email to a vulnerable internet-facing server and potentially run commands, though Redmond notes the flaw affects only servers running Zimbra's optional SNMP monitoring package with notifications enabled.
REG AD
Zimbra fixed the flaw in version 10.1.20 on July 20, but CVE-2026-73570 wasn't publicly disclosed until August 13. Between July 28 and August 7, Redmond spotted two different scanning tools probing the same part of Zimbra later used in attacks.
REG AD
At first, the activity appears to have focused on finding vulnerable servers and testing the flaw. The attackers used a collection of common network utilities to make vulnerable systems call back to infrastructure they controlled, confirming they could execute commands.
Once they found servers that played ball, things got messier. Microsoft's investigation found attackers deploying web shells and reverse shells, escalating their privileges, installing tools for persistent remote access, and running malicious code directly in memory.
Some even tidied up after themselves. Microsoft said attackers temporarily changed permissions on public directories to plant web shells, then restored the original settings afterward in an apparent attempt to make their meddling harder to spot.
The intruders also explored the wider Zimbra environments they landed in, identifying other mail servers and looking for trusted connections they could use to move between them. In some cases, existing SSH relationships between Zimbra systems gave them a route to neighboring servers.
On at least one compromised machine, attackers turned their initial foothold into root access. They then set things up to keep running commands with the highest privileges without needing a password.
Mailboxes were, unsurprisingly, also on the shopping list. Microsoft said attackers hunted for Zimbra credentials and authentication secrets that could potentially be used to access user accounts. One malicious tool it uncovered was built specifically to extract service account credentials and pull mailbox information from Zimbra's databases.
In another incident, attackers bundled recent mailbox backups into an archive and tried to ship the haul to Azure Blob Storage using Microsoft's own AzCopy utility. Microsoft said it couldn't confirm from the evidence available whether the transfer actually succeeded.
The company saw affected organizations across multiple regions and industries, with the attacks ranging from automated exploitation to more deliberate hands-on-keyboard activity. It hasn't attributed the activity to a particular crew.
REG AD
Admins running versions earlier than Zimbra 10.1.20 should update to 10.1.20 or later, while those unable to patch can reduce their exposure by removing the optional SNMP package or disabling SNMP notifications.
Attackers, meanwhile, appear to have gotten there early, with Microsoft spotting probes for the flaw more than two weeks before it was publicly disclosed. ®