The news
Attackers exploited a serious flaw in the Zimbra Collaboration Suite (ZCS) email server weeks before it was publicly disclosed, according to an analysis Microsoft published on September 30. The bug, CVE-2026-73570, lets an unauthenticated attacker run operating system commands by sending a specially crafted email to an exposed server.
The flaw is an OS command injection in how Zimbra processes SNMP notifications. SNMP, the Simple Network Management Protocol, is used to monitor servers. It is rated 8.9 out of 10 on the CVSS severity scale and affects ZCS versions before 10.1.20, according to SecurityWeek. The Register reported that only servers with the optional SNMP monitoring package and its notifications enabled are exposed.
Zimbra shipped the fix in version 10.1.20 on July 20, 2026. The flaw was publicly disclosed on August 13. Between those dates, from July 28 to August 7, Microsoft detected two different scanning tools probing the vulnerability, The Register reported. CERT Polska, Poland's national computer emergency team, released indicators of compromise on August 17 after confirming active exploitation, according to SecurityWeek. The Hacker News reported that the US Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies an August 24 deadline to fix it.
Microsoft Threat Intelligence said it tracked exploitation across multiple regions and industries, as reported by The Register. Early activity was reconnaissance to confirm that commands would run. Later, attackers deployed JSP web shells, small scripts that give remote control of a server, in Jetty and mailboxd directories, opened reverse shells and escalated to root, in part by modifying /etc/pam.d/sudo, according to The Hacker News.
Attackers also extracted Zimbra credentials and authentication secrets, harvested mailbox data and MySQL database contents, and installed a remote-access agent called Zimclient2 for persistence, The Hacker News reported. The Register said some tried to exfiltrate mailbox backups to Azure Blob Storage using AzCopy, and that the activity ranged from automated exploitation to hands-on-keyboard work. Not every victim showed the full attack chain.
The numbers
- CVSS severity score
- 8.9
- Fixed version
- ZCS 10.1.20 (July 20, 2026)
- Scanning observed by Microsoft
- July 28 to August 7, 2026
- Public disclosure
- August 13, 2026
Why CEOs should care
For CISOs, a patch date is not a safety date. This bug was fixed on July 20 but drew little attention until August 13, and Microsoft says attackers were already probing it in between. Any Zimbra server that stayed on an older version through that window should be treated as possibly compromised. Ask your team three things: are we on 10.1.20 or later, is the SNMP package or its notifications enabled, and have we checked Jetty and mailboxd directories for unknown JSP files?
Patching alone will not remove an intruder. The reported actions include root access, changed sudo settings, stolen authentication secrets and a persistent remote-access agent. If you find signs of compromise, rotate Zimbra and connected credentials, review SSH keys, check systemd services for unknown entries, and look for outbound transfers to cloud storage such as Azure Blob Storage. Use the CERT Polska indicators and Microsoft's guidance as a starting point.
For boards and general counsel, email servers hold the most sensitive conversations in a company. Mailbox theft can trigger breach-notification duties and expose deal and legal communications. If you cannot patch quickly, the sources say to disable the SNMP package and notifications and restrict network access to SNMP and SMTP ports.
The bigger picture
Self-hosted email remains a frequent target because a single server holds a whole organization's mail and passwords. This case also shows a gap that attackers exploit: quietly released fixes. When a vendor ships a patch before publishing an advisory, defenders who wait for a CVE notice can fall behind attackers who study the code changes.
What’s next
Expect more indicators from Microsoft and national CERTs as investigations continue. Zimbra customers should confirm patch status across every node, including clusters, since attackers reportedly moved between nodes using compromised SSH identities.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








