Microsoft warns of active exploitation of a Zimbra Collaboration Suite flaw

The unauthenticated CVE-2026-73570 flaw in Zimbra’s SNMP notifications allows command execution on vulnerable mail servers. A fix has been available since July.

CVE-2026-73570 in Zimbra Collaboration Suite is being actively exploited to compromise internet-facing mail servers. In a published analysis, Microsoft described cases in which initial access was followed by the deployment of webshells, privilege escalation, persistence, and the collection of email and authentication data.

The vulnerability is an unauthenticated operating-system command injection in the SNMP notification path. It is tracked as CVE-2026-73570, and the NVD assigns it a CVSS score of 8.9 as well as active-exploitation status. Zimbra released a fix in version 10.1.20 on July 20, 2026.

CVE-2026-73570 in Zimbra requires a specific configuration

Not all Zimbra Collaboration Suite installations are affected in the same way. Exploitation requires the zimbra-snmp package to be installed and SNMP notifications to be enabled at the same time. Versions older than 10.1.20 are vulnerable with this configuration.

According to Microsoft, the attacker does not need to log in. They can execute commands under the zimbra account, creating an opportunity for further steps on the system. For publicly accessible servers, this is particularly risky because mail infrastructure processes sensitive communications and stores service passwords or authentication keys.

Webshells, reverse shells, and secret collection

In compromised environments, Microsoft observed JSP webshells and reverse shells. Attackers used them to remotely execute additional commands, escalate privileges, and maintain access to the server.

The analysis also describes the collection of email, mail, and authentication data. Signs of compromise include unknown JSP files in Zimbra web directories, suspicious systemd services, and changes to PAM or sudo configuration.

Microsoft observed the creation of archives and an attempt to transfer data. However, it has no evidence that exfiltration from a specific analyzed server was successfully completed. The identity or motivation of the attackers has also not been publicly confirmed. In addition, individual compromised instances may not have exhibited all the attack stages described in the analysis.

Recommended steps for Zimbra administrators

Microsoft recommends upgrading to Zimbra Collaboration Suite 10.1.20 or later without delay. Organizations that cannot upgrade immediately can temporarily reduce exposure by uninstalling the zimbra-snmp package, disabling SNMP notifications, and restricting access to SNMP and SMTP services.

However, the update itself will not remove any webshells or persistence mechanisms inserted before the fix was deployed. Administrators should therefore check servers for the listed indicators of compromise and rotate affected Zimbra secrets, including service passwords and authentication keys.

Further developments will show whether Zimbra or national CERT teams publish new indicators of compromise or information about the scope of affected organizations. Independently verified findings about whether email data was successfully stolen in some incidents will also be important.

Sources

  • Microsoft Security Blog – Primary analysis of the observed exploitation, post-exploitation steps, secret collection, attempted exfiltration, and recommended mitigations.
  • Zimbra Blog – Confirms the release of Zimbra Collaboration Suite 10.1.20 and the fix for the critical SNMP vulnerability.
  • NVD – Confirms the technical description of the CVE, versions affected before 10.1.20, the CVSS score of 8.9, and the record of active exploitation.
  • Ars Technica – Independently summarizes Microsoft’s newly published findings and notes that successful exfiltration has not been confirmed.

Verified and updated: 10/01/2026 06:25

Sharing