Microsoft Threat Intelligence published an analysis on September 30 covering CVE-2026-73570 in Zimbra Collaboration Suite, also known as ZCS. The flaw allows unauthenticated command injection and has a CVSS score of 8.9. It affects every version before 10.1.20, although Zimbra released a fix on July 20. Microsoft says exploitation began by late July at the latest and has compromised at least several hundred servers.
The vulnerable component processes Zimbra SNMP notifications. Exploitation requires the optional zimbra-snmp package and enabled notifications. An attacker can send specially crafted SMTP requests that trigger an error and then run arbitrary system commands with the privileges of the zimbra user.
Microsoft observed scanning activity on July 28 and August 7. Both observations came after the patch and before public disclosure on August 13 through the NVD. The probes used HTTP requests, DNS checks, ICMP checks and in-band identity tests. Commands included curl, wget, ping, nslookup and id. The traffic contacted oast[.]fun, requestrepo[.]com and campaign infrastructure at bypass[.]eu[.]org. HTTP probes carried the User-Agent ZB73570, which Microsoft says may indicate that attackers studied the patch before the CVE details became public.
The attackers deployed malicious JSP pages, or web shells, in the Jetty and mailboxd directories. They copied the files to other mailbox nodes and sometimes changed the public directory permissions temporarily. A disguised systemd unit called zimlog.service was also installed. Its timestamps were altered to resemble sshd.service.
The campaign used zmmailboxd.out as a symbolic link to /etc/pam.d/sudo. This caused the privileged zmmailboxdmgr process to run. Attackers then moved laterally through the infrastructure and exfiltrated data, including stolen secrets. Microsoft has not attributed the activity to a named actor. Victims span several regions and sectors, and the operation combines automated and manual actions.
Microsoft considers every Zimbra instance that was still unpatched at the end of July potentially compromised. Installing the update is the priority. If that cannot happen immediately, administrators should remove zimbra-snmp, disable SNMP notifications and restrict SNMP and SMTP access to trusted hosts.
After patching, administrators should rotate all zimbraPreAuthKey and zimbraAuthTokenKey keys. They should inspect /etc/sudoers.d/, including 81_metric, /etc/pam.d/ and systemd units such as zimlog.service, chronyd-helper.service and syslog_init.service. They should also search every node for unexpected JSP files and *_jsp.java files.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.