Hackers started exploiting a high-severity OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) shortly after patches were rolled out, before public disclosure, Microsoft reports.
Tracked as CVE-2026-73570 (CVSS score of 8.9), the flaw exists because, in ZCS before 10.1.20, untrusted input during SNMP notification processing is improperly sanitized.
Thus, if the zimbra-snmp package has been installed and SNMP notifications have been enabled, an attacker could trigger the security defect via specially crafted SMTP requests.
Successful exploitation of the bug allows unauthenticated attackers to achieve remote code execution with the privileges of the Zimbra user.
Patches for CVE-2026-73570 were rolled out on July 20 in ZCS version 10.1.20, and the vulnerability was publicly disclosed on August 13.
Poland’s CERT Polska flagged the security defect as exploited and released indicators of compromise (IoCs) on August 17, but in-the-wild exploitation started between patching and public disclosure.
“Between July 28 and August 7, after a fix became available on July 20 but before public disclosure on August 13, Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point,” Microsoft says.
The reconnaissance activity used an execution path that was later seen during exploitation, and was meant to validate command execution via lightweight out-of-band probes, without delivering a payload.
As part of the observed follow-up exploitation activity, the attackers deployed JSP webshells to publicly accessible application directories, executed content through wget or curl, launched background processes, and established interactive reverse shells.
“Multiple JSP webshells were deployed across Jetty and mailboxd application paths, including additional copies on peer mailbox nodes. This provided alternative access paths across different Zimbra configurations and reduced reliance on a single webshell,” Microsoft notes.
The attackers then mapped clusters, fingerprinted the environment, checked for the Zimbra SSH identity, escalated privileges to root using legitimate Zimbra tools, and deployed a secondary persistence mechanism using a systemd service named zimlog.service.
According to Microsoft, the hackers targeted Zimbra’s centralized service and authentication secrets for credential exfiltration, and used the login material for authenticated LDAP queries that allowed them to retrieve high-value secrets.
They also used Zimbra’s existing SSH identity to access other nodes in the cluster, used HTTP and HTTPS callbacks to validate command execution, and deployed “a full remote-access agent providing interactive shell access, bidirectional file operations, and SOCKS5 proxying”.
Zimbra Collaboration Suite users are advised to update their instances to version 10.1.20 or later, uninstall the optional package, disable the vulnerable configuration, restrict SNMP and SMTP access, and check their environments for potential compromise.
Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack
Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
