Microsoft observed probing for Zimbra’s CVE-2026-73570 from July 28 through August 7, 2026, before the vulnerability was publicly disclosed on August 13. But Zimbra 10.1.20, which contains the fix, had already been released on July 20. The activity therefore occurred after a patch was available—not throughout a period when the flaw was necessarily unknown and unpatched.
What is CVE-2026-73570?
CVE-2026-73570 is an unauthenticated operating-system command-injection vulnerability in the SNMP notification path of Zimbra Collaboration Suite (ZCS). Singapore’s Cyber Security Agency rated it CVSS v3.1 8.9 out of 10 and advised administrators to update immediately in its August 21, 2026 alert.
The affected configuration is ZCS earlier than 10.1.20 with the optional zimbra-snmp package installed and SNMP notifications enabled. Microsoft says an attacker does not need to authenticate or obtain user interaction to exploit the flaw. If either the optional package is absent or SNMP notifications are disabled, the described attack path is not enabled in that configuration.
How the command injection works
Microsoft describes a specially crafted SMTP request that places attacker-controlled input into Zimbra’s SNMP notification processing. A service-state change can trigger health monitoring; swatchdog then incorporates the untrusted value into a shell invocation of snmptrap. When the vulnerable path is available, commands can execute with the privileges of the zimbra service account.
#1 Best Overall
What the timeline says about exploitation
| Date | Event | What it establishes |
|---|---|---|
| July 20, 2026 | Zimbra 10.1.20, containing the remediation, was released. | Microsoft reports that the fix was available before the observed probing and public disclosure. |
| July 28–August 7, 2026 | Microsoft observed probing using two distinct out-of-band scanning tools. | These are observed tools and activity, not a victim count or proof that every probe compromised a server. |
| August 13, 2026 | CVE-2026-73570 was publicly disclosed. | The disclosure followed both the fix release and the probing Microsoft reports. |
| August 21, 2026 | CISA added the CVE to its Known Exploited Vulnerabilities catalog, according to the Canadian Centre for Cyber Security. | The Canadian Centre’s advisory was updated that day. |
Microsoft’s September 30, 2026 account says the probes tested command execution using HTTP, DNS, ICMP, and in-band checks. Reported commands included curl, wget, ping, nslookup, and id. This supports a precise answer to “Was it exploited before public disclosure?”: Microsoft observed probing during the pre-disclosure interval, but the patch had been available since July 20. The report does not establish that every probed server was compromised or that the flaw remained unknown until August 13.
What Microsoft says attackers did—and what is not confirmed
Across investigated activity, Microsoft reports JSP web shells, reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution. It also reports access to email and collection of authentication and mailbox data. These are behaviors documented across the activity, not a checklist that every affected host necessarily exhibited.
Rank #2
- 【Perfectly Fit in Server Aprons】: Our black server book size is 8.15" x 5.12" x 0.59", which can hold a regular guest checkbook and is handy to be carried in a server apron pocket, won’t be too tight or too big, efficiency as a server money holder.
- 【Stay Organized All in Needs】: 9 compartments and 1 pen holder in one serving book, with a zipper pocket to store your coins, changes, and money. Multi-functional pockets to organize checkbooks, cash, ticket books, server pads, credit cards, coupons, or any other paper documents, nice waitress accessories partner for servers.
- 【Waterproof Leather Material】: The waitress book is made of premium sturdy PU leather, Eco-friendly and odorless, features excellent workmanship and tight stitching, easy to clean. Plus an elastic pen loop to be a nice waitstaff organizer to help you hold the pen that is always away from home and improve the service speed.
- 【Portable and Long-lasting】: Our server books for the waiter are lightweight to carry around, and sturdy as a guest checkbook holder, premium material makes them sturdy and won’t easily deform or press the belly when bent over.
- 【100% Satisfaction Guarantee】: We hope you love your server book wallet and place your order with confidence, all of our men’s & women’s server books are backed by a replacement guarantee. Any questions will be answered within 24 hours.
In one incident, Microsoft describes mailbox backups being archived to /opt/zimbra/final.tar.gz and an attempted transfer to Azure Blob storage using AzCopy. Microsoft explicitly says available evidence did not confirm that the transfer completed successfully. A staging archive or transfer attempt should not be described as verified exfiltration.
Microsoft says its composite attack-chain diagram combines behaviors seen across confirmed compromises; no individual host necessarily showed every stage. Its report describes impacted organizations in more than one region and industry but gives no victim total, so it does not support a population-wide estimate.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- 100% Satisfaction Warranty – Our servers book for waitress organization are handcrafted with elegant stitching that lasts. We take pride in offering our customers a waitress book made to exceptional quality standards. To ensure satisfaction, every waiters checkbook is backed by a 1-YEAR WARRANTY. If you are not 100% SATISFIED for any reason we will send you a replacement. No Questions Asked
- Holds up under Pressure – When you're taking orders the last thing you need is a flimsy waiter book that keeps bending. Our 8”x5” server books for waitress organization is the only one with a premium reinforced dual inner core. Providing an unmatched sturdy reliable writing surface that will last for years
- On Another Level – Halt the endless cycle of replacing your cheap thin black server book that barely lasts a week. This serving book for waitresses can become your permanent partner. Crafted with overwhelmingly strong attention to detail, the waiter checkbook offers an unparalleled value that you won’t regret investing in
- Scribble In Style – Impression is everything. You’re making a statement when you bring out this sleek vegan leather serving book. Our serving books have no logos or images and exquisite stitching for a professional feel your colleagues will envy
- Stay Calm and Collected – Whether you have 1 table or 7, organization is key. This server checkbook has 9 versatile pockets including a durable metal zipper to keep your cash secure. Stay on top of everything with this deluxe server book organizer and bring superior service to every customer
Which Zimbra versions and configurations need attention?
Zimbra’s security advisories list the SNMP notification command-injection fix in 10.1.20. Administrators should upgrade affected installations to 10.1.20 or later. The Canadian Centre for Cyber Security’s advisory identifies affected Zimbra releases as of the August 13 disclosure.
Quick Recap
Best Value
- The outside is made with holographic glitter material, which changes color depending on the viewing angle. The clear coating makes it smooth so the color doesn’t rub off. It can be cleaned with a damp cloth.
- The interior is made with complimentary colored vegan leather PU, which makes the wallet more flexible and beautiful.
- Small in size (4.7” X 7.5”), it will hold a regular guest check book (which is not included), and can be put into an apron pocket.
- The wallet has 7 pockets and compartments, which can accommodate cash, business cards, credit cards, receipts, etc. to help the server be organized. It also has a pen/pencil holder and can be used as a personal organizer for travel, school, or daily work.
- Perfect for Waitstaff: Ideal for using at restaurants, cafes, bars, etc. Great for waitstaff, servers, and bartenders
Rank #4
- Include: 1x serverbook(not include guest check)
- Design: Unique design deluxe and durable server book to let your outstanding.Fit Server Apron well.
- Function: Have 8 slot.One slot for checkbook,3 slots for cards,3 slots receipt or money or other daily food special.also a slot for pen
- Size: 7.6x4.9x0.78inch,6oz
- Material: Made with high quality PU leather
- Earlier than 10.1.20, with
zimbra-snmpinstalled and SNMP notifications enabled: matches the vulnerable configuration described by Microsoft. - 10.1.20 or later: includes the remediation identified by Zimbra.
- Optional package absent or notifications disabled: the specific SNMP notification path described here is not available in that configuration, though this alone does not establish that a system is free of other vulnerabilities or prior compromise.
How to mitigate CVE-2026-73570
- Upgrade ZCS to 10.1.20 or later. Microsoft’s guidance is to patch immediately. Confirm the installed version after the update.
- If the upgrade must wait, reduce exposure. Microsoft recommends uninstalling the optional
zimbra-snmppackage, disabling SNMP notifications, and restricting SNMP and SMTP access to trusted hosts. These are interim controls, not substitutes for installing the fix. - Investigate internet-facing servers for compromise. Treat evidence of a reverse shell as a priority incident. Scope and contain affected systems, then review services and persistence mechanisms. Rotate Zimbra authentication secrets and domain
zimbraPreAuthKeyvalues as appropriate to the incident. - Look beyond malware-family alerts. Microsoft says some consequential activity used a plain interactive shell without a malware-family label. An absence of a named malware detection does not by itself rule out compromise.
- Handle patching and incident response separately. Updating closes the vulnerable version’s attack path; it does not prove that a server exposed earlier was never compromised.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

