News Date: 2026-09-30
Internet-facing email infrastructure is once again demonstrating why it belongs near the top of every enterprise patching list. Microsoft has detailed real-world exploitation of CVE-2026-73570, a Zimbra Collaboration Suite vulnerability that can allow attackers to execute operating-system commands by sending specially crafted SMTP traffic.
An Email Can Trigger Server-Side Commands
The vulnerability exists in Zimbra's SNMP notification path. Exploitation requires the optional zimbra-snmp package to be installed and SNMP notifications to be enabled, but it does not require valid credentials or interaction from a user. A malicious request can introduce attacker-controlled input into a shell command executed under the Zimbra service account.
Microsoft observed reconnaissance and probing after Zimbra released version 10.1.20 on July 20, but before the vulnerability was publicly disclosed on August 13. The subsequent intrusions went far beyond simple vulnerability testing. Attackers installed multiple JSP web shells, opened reverse shells and used trusted relationships within Zimbra clusters to move between servers.
The Real Target Was the Trust Around Email
Compromised systems were searched for service credentials, authentication keys, two-factor authentication secrets and mailbox information. In some cases, attackers escalated to root by abusing legitimate Zimbra components and Linux authentication mechanisms. They also created disguised system services, manipulated timestamps and deployed remote-access agents with encrypted communications and proxy capabilities.
This is especially serious because a mail server is more than a message repository. It often holds password-reset emails, confidential conversations, legal records and authentication material. A compromised server may therefore become a platform for identity theft, internal phishing and movement into connected systems.
Recommended Defensive Actions
- Upgrade every Zimbra instance to version 10.1.20 or later.
- Remove zimbra-snmp or disable SNMP notifications if immediate patching is impossible.
- Inspect web application directories for unexpected JSP files and compiled servlet artifacts.
- Review system services, sudo configuration, SSH keys and recent permission changes.
- Rotate Zimbra preauthentication keys, token-signing material and exposed service credentials.
In my view, organizations should treat evidence of a reverse shell as a confirmed breach rather than a blocked exploit attempt. Removing one payload is not enough when attackers may have installed several independent access methods. Full forensic scoping across every node in the Zimbra cluster is essential.
