Pandorex
Security

Zimbra CVE-2026-73570: Microsoft Traces Attacks From Incoming Mail to Root

Published Pandorex Redaktion·4 min read
—
Illustration: a crafted email follows a red command path into an open maintenance panel on a mail server and leaves a persistence hook inside.
Editorial illustration · Pandorex

In brief: Microsoft has reconstructed attacks exploiting CVE-2026-73570 on Zimbra mail servers. A crafted SMTP request executes operating-system commands without authentication where the optional zimbra-snmp package and SNMP notifications are active. Zimbra 10.1.20 has fixed the flaw since July 20.

From incoming SMTP to a shell

No user needs to open a message. Attackers insert shell metacharacters into an SMTP request. Zimbra monitoring passes the value to snmptrap, which executes it as the service account.

Not every Zimbra deployment is exposed. Zimbra and NVD say the optional SNMP component and notifications must be active; versions before 10.1.20 are vulnerable. NVD lists the flaw in CISA's Known Exploited Vulnerabilities catalogue. NIST provides no score of its own; the CNA score is 8.9.

Patched before disclosure, attacked afterwards

Microsoft observed callback probes against this exact execution path between July 28 and August 7. The patch was available, but the CVE was not disclosed until August 13. Confirmed compromises then included JSP web shells, reverse shells, memory-backed execution and abuse of legitimate Zimbra helpers to grant the service account root privileges.

Attackers also installed disguised systemd services and collected central Zimbra service credentials, authentication keys and mailbox metadata. Updating therefore closes only the entry point. Where earlier compromise is plausible, administrators need to hunt for persistence and rotate affected secrets; for the earliest activity, Microsoft explicitly recommends archived logs beyond the usual 30-day window.

Pandorex Analysis

Golem's August report was technically accurate: it separated 12,000 internet-reachable Zimbra systems from the unknown number that were vulnerable. Microsoft now supplies the missing evidence of what happened after exploitation. The operational consequence is broader than updating to 10.1.20 or later: systems patched only after late July should be reviewed retrospectively for web shells, altered PAM or sudo configuration, suspicious systemd services and stolen keys.

Sources and references

Sources used for the facts and context in this article.

  1. Zimbra, fortlaufend aktualisiert: Zimbra Security Advisorieswiki.zimbra.com
  2. NIST NVD, 13.08.2026: CVE-2026-73570 Detailnvd.nist.gov
  3. Microsoft Security Research, 30.09.2026: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570microsoft.com
  4. Golem, 21.08.2026, ergänzt 25.08.2026: Bis zu 12.000 Systeme gefährdet: Zimbra-Server werden attackiertgolem.de

How Pandorex researches and corrects articles

Comments

Sign in to write a comment.

Swipe up
Next Article

Nvidia Draws Boundaries Around AI Agents With OpenShell and BlueField-4

Security