In brief: Microsoft has reconstructed attacks exploiting CVE-2026-73570 on Zimbra mail servers. A crafted SMTP request executes operating-system commands without authentication where the optional zimbra-snmp package and SNMP notifications are active. Zimbra 10.1.20 has fixed the flaw since July 20.
From incoming SMTP to a shell
No user needs to open a message. Attackers insert shell metacharacters into an SMTP request. Zimbra monitoring passes the value to snmptrap, which executes it as the service account.
Not every Zimbra deployment is exposed. Zimbra and NVD say the optional SNMP component and notifications must be active; versions before 10.1.20 are vulnerable. NVD lists the flaw in CISA's Known Exploited Vulnerabilities catalogue. NIST provides no score of its own; the CNA score is 8.9.
Patched before disclosure, attacked afterwards
Microsoft observed callback probes against this exact execution path between July 28 and August 7. The patch was available, but the CVE was not disclosed until August 13. Confirmed compromises then included JSP web shells, reverse shells, memory-backed execution and abuse of legitimate Zimbra helpers to grant the service account root privileges.
Attackers also installed disguised systemd services and collected central Zimbra service credentials, authentication keys and mailbox metadata. Updating therefore closes only the entry point. Where earlier compromise is plausible, administrators need to hunt for persistence and rotate affected secrets; for the earliest activity, Microsoft explicitly recommends archived logs beyond the usual 30-day window.
Pandorex Analysis
Golem's August report was technically accurate: it separated 12,000 internet-reachable Zimbra systems from the unknown number that were vulnerable. Microsoft now supplies the missing evidence of what happened after exploitation. The operational consequence is broader than updating to 10.1.20 or later: systems patched only after late July should be reviewed retrospectively for web shells, altered PAM or sudo configuration, suspicious systemd services and stolen keys.
