Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Zimbra flaw CVE-2026-73570 was exploited before disclosure through crafted emails, Microsoft says

Attackers probed and exploited the Zimbra mail server bug after a quiet fix but before public disclosure, then planted web shells and pulled credentials and mailbox data.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Microsoft says attackers were probing CVE-2026-73570 in Zimbra from July 28 to August 7, before its August 13 disclosure.
  • 2A crafted email to an exposed server could run commands without login or user action on setups using optional SNMP notifications.
  • 3Attackers planted web shells, gained root, took credentials and mailbox data, and tried to copy backups to Azure storage.

The news

Attackers exploited a serious flaw in the Zimbra Collaboration Suite (ZCS) email server weeks before it was publicly disclosed, according to an analysis Microsoft published on September 30. The bug, CVE-2026-73570, lets an unauthenticated attacker run operating system commands by sending a specially crafted email to an exposed server.

The flaw is an OS command injection in how Zimbra processes SNMP notifications. SNMP, the Simple Network Management Protocol, is used to monitor servers. It is rated 8.9 out of 10 on the CVSS severity scale and affects ZCS versions before 10.1.20, according to SecurityWeek. The Register reported that only servers with the optional SNMP monitoring package and its notifications enabled are exposed.

Zimbra shipped the fix in version 10.1.20 on July 20, 2026. The flaw was publicly disclosed on August 13. Between those dates, from July 28 to August 7, Microsoft detected two different scanning tools probing the vulnerability, The Register reported. CERT Polska, Poland's national computer emergency team, released indicators of compromise on August 17 after confirming active exploitation, according to SecurityWeek. The Hacker News reported that the US Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies an August 24 deadline to fix it.

Microsoft Threat Intelligence said it tracked exploitation across multiple regions and industries, as reported by The Register. Early activity was reconnaissance to confirm that commands would run. Later, attackers deployed JSP web shells, small scripts that give remote control of a server, in Jetty and mailboxd directories, opened reverse shells and escalated to root, in part by modifying /etc/pam.d/sudo, according to The Hacker News.

Attackers also extracted Zimbra credentials and authentication secrets, harvested mailbox data and MySQL database contents, and installed a remote-access agent called Zimclient2 for persistence, The Hacker News reported. The Register said some tried to exfiltrate mailbox backups to Azure Blob Storage using AzCopy, and that the activity ranged from automated exploitation to hands-on-keyboard work. Not every victim showed the full attack chain.

The numbers

CVSS severity score
8.9
Fixed version
ZCS 10.1.20 (July 20, 2026)
Scanning observed by Microsoft
July 28 to August 7, 2026
Public disclosure
August 13, 2026

Why CEOs should care

For CISOs, a patch date is not a safety date. This bug was fixed on July 20 but drew little attention until August 13, and Microsoft says attackers were already probing it in between. Any Zimbra server that stayed on an older version through that window should be treated as possibly compromised. Ask your team three things: are we on 10.1.20 or later, is the SNMP package or its notifications enabled, and have we checked Jetty and mailboxd directories for unknown JSP files?

Patching alone will not remove an intruder. The reported actions include root access, changed sudo settings, stolen authentication secrets and a persistent remote-access agent. If you find signs of compromise, rotate Zimbra and connected credentials, review SSH keys, check systemd services for unknown entries, and look for outbound transfers to cloud storage such as Azure Blob Storage. Use the CERT Polska indicators and Microsoft's guidance as a starting point.

For boards and general counsel, email servers hold the most sensitive conversations in a company. Mailbox theft can trigger breach-notification duties and expose deal and legal communications. If you cannot patch quickly, the sources say to disable the SNMP package and notifications and restrict network access to SNMP and SMTP ports.

The bigger picture

Self-hosted email remains a frequent target because a single server holds a whole organization's mail and passwords. This case also shows a gap that attackers exploit: quietly released fixes. When a vendor ships a patch before publishing an advisory, defenders who wait for a CVE notice can fall behind attackers who study the code changes.

What’s next

Expect more indicators from Microsoft and national CERTs as investigations continue. Zimbra customers should confirm patch status across every node, including clusters, since attackers reportedly moved between nodes using compromised SSH identities.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

ZimbraMicrosoftCVE-2026-73570CERT PolskaEmail security

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.