Microsoft reported on September 30, 2026, that it had tracked exploitation of CVE-2026-73570, an unauthenticated command-injection flaw in Zimbra Collaboration Suite (ZCS). Microsoft observed two distinct scanning tools probing the vulnerable path from July 28 through August 7, 2026. It identified August 13 as the date the vulnerability was publicly disclosed.

How the Zimbra attack path works

Microsoft describes CVE-2026-73570 as command injection in ZCS’s SNMP notification processing. Command injection occurs when untrusted input can cause a system to run commands. In this case, a specially crafted SMTP request can introduce that input into SNMP processing; the commands can then run with the privileges of the zimbra service account.

The attack path Microsoft described requires both the optional zimbra-snmp package to be installed and SNMP notifications to be enabled. Microsoft characterizes the flaw as unauthenticated: the described request does not require an attacker to log in, provided those configuration conditions are met.

What Microsoft observed

Microsoft reported web shells, reverse shells, privilege escalation, persistent remote-access tools, and memory-backed execution across the compromises it investigated. It also observed automated payload delivery and hands-on activity. These behaviors were reported across multiple systems; the account does not mean that every behavior occurred on every server.

Mailbox-data collection and remediation

Microsoft said attackers accessed email and collected mailbox and authentication data. It also observed archive creation and transfer activity, but could not verify that the data was successfully exfiltrated.

Zimbra Collaboration Suite 10.1.20, released July 20, 2026, contains the remediation for CVE-2026-73570. Microsoft recommends version 10.1.20 or later.