Microsoft said on September 30, 2026, that it had tracked exploitation of CVE-2026-73570 in Zimbra Collaboration Suite. It observed two distinct scanning tools probing the vulnerable path from July 28 through August 7—after Zimbra released a fix on July 20, but before public disclosure on August 13.

The flaw allows operating-system command execution without authentication under a specific Zimbra configuration. Microsoft also reported post-compromise activity in investigated environments, including collection of credentials and mailbox-related data.

Which Zimbra systems were affected?

Microsoft said the vulnerable path required the optional zimbra-snmp package to be installed and SNMP notifications to be enabled. A crafted SMTP request could then trigger operating-system commands with the privileges of the zimbra service account, without authentication or user interaction.

What Microsoft reported after access

Microsoft described web shells and reverse shells, persistence, privilege escalation, movement between Zimbra hosts using existing SSH trust, and collection of service credentials, authentication secrets, and mailbox-related data. These behaviors came from multiple investigated compromises; Microsoft said its composite attack chain did not mean every stage occurred on every host.

Microsoft also reported an attempt to transfer archived mailbox backups to Azure Blob Storage using AzCopy. It could not confirm whether the transfer completed, and it did not attribute the activity to a named threat group.

Zimbra 10.1.20 lists the fix

Zimbra released version 10.1.20 on July 20, 2026. Its release notes list a command-injection fix in the SNMP monitoring component for systems with SNMP notifications enabled.

CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog on August 21, 2026, with a federal remediation deadline of August 24.