CVE-2026-73570 was fixed in Zimbra 10.1.20 on July 20 but not publicly disclosed until August 13 — and Microsoft saw probing activity against the same flaw between July 28 and August 7.
CVE-2026-73570 and Zimbra's SNMP monitoring package
Microsoft Threat Intelligence reported that CVE-2026-73570 is an unauthenticated command‑injection vulnerability in Zimbra Collaboration Suite that can allow an attacker to run commands on an exposed mail server without credentials or user interaction. According to Redmond, the flaw is exploitable by sending a specially crafted email to a vulnerable, internet‑facing server, but only affects installations running Zimbra's optional SNMP monitoring package with notifications enabled.
Microsoft Threat Intelligence timeline: patch, scans, and disclosure
Zimbra issued a fix in version 10.1.20 on July 20. The CVE was publicly disclosed on August 13. Microsoft said it observed two different scanning tools probing the same portion of Zimbra later used in attacks during the period between July 28 and August 7 — a window that places some attacker activity more than two weeks ahead of public disclosure.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAttackers' techniques: shells, privilege escalation, and persistence
Once attackers found vulnerable servers, Microsoft observed a rapid escalation of activity. Initial scans and tests gave way to hands‑on deployment of remote access mechanisms and privilege escalation. The activity Microsoft described included:
- making vulnerable systems call back to attacker‑controlled infrastructure using common network utilities to confirm command execution;
- deploying web shells and reverse shells;
- escalating privileges, including at least one case that resulted in root access;
- installing tools intended for persistent remote access and running malicious code directly in memory;
- temporarily changing permissions on public directories to plant web shells and then restoring original permissions, apparently to hinder detection.
Mailbox theft, credential harvesting, and an AzCopy export attempt
Mailboxes and authentication secrets were a clear objective. Microsoft said intruders searched for Zimbra credentials and other authentication secrets that could enable account access. Investigators found at least one tool designed to extract service account credentials and pull mailbox information from Zimbra databases.
In a separate incident, attackers packaged recent mailbox backups into an archive and attempted to transfer the archive to Azure Blob Storage using Microsoft's AzCopy utility. Microsoft reported it could not confirm from the available evidence whether that export ultimately succeeded.
What this means for Zimbra administrators, affected organizations, and incident responders
- Zimbra administrators running versions earlier than 10.1.20: Microsoft advises updating to 10.1.20 or later. For those who cannot immediately patch, Redmond recommended removing the optional SNMP package or disabling SNMP notifications to reduce exposure.
- Affected organizations across multiple regions and industries: Microsoft observed activity ranging from automated exploitation to more deliberate hands‑on‑keyboard intrusions, and reported that attackers explored wider Zimbra environments for other mail servers and trusted connections that could enable lateral movement.
- Incident responders and forensic teams: Microsoft noted that attackers sometimes restored permissions after planting web shells and leveraged existing SSH relationships between Zimbra systems to move laterally — behaviors that responders should consider when hunting for signs of compromise and when assessing trust relationships between mail servers.
Microsoft did not attribute the activity to any particular crew. The sequence captured by Redmond — scans and command‑execution tests before disclosure, followed by web shells, credential harvesting, privilege escalation to root, and an attempted AzCopy export — shows a full attack chain that moved from reconnaissance to data‑exfiltration attempts and persistence. For administrators who manage internet‑facing Zimbra servers with SNMP notifications enabled, the advice is concrete and immediate: patch to 10.1.20 or remove/disable the SNMP component.




