Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Attackers are exploiting CVE-2026-73570, an unauthenticated command-injection flaw in Zimbra Collaboration Suite (ZCS), to run commands as the zimbra service account. Microsoft observed intruders using that access to install JSP web shells, establish other forms of access and collect service credentials and authentication keys. The cited vulnerable configuration is ZCS before 10.1.20 with the optional zimbra-snmp package installed and SNMP notifications enabled. Administrators should upgrade and, if compromise is possible, investigate and rotate exposed secrets as well.

How the Zimbra flaw gives attackers access

CVE-2026-73570 is an unauthenticated operating-system command-injection vulnerability in ZCS’s SNMP notification path. According to Microsoft Security Research’s September 30, 2026 report, a specially crafted SMTP request can trigger the vulnerable processing and let an attacker execute commands as the zimbra service account. Singapore’s Cyber Security Agency describes the affected condition as ZCS versions before 10.1.20 when zimbra-snmp is installed and SNMP notifications are enabled.

Those conditions matter when assessing exposure: a server running an earlier release is not necessarily in the specifically described vulnerable configuration if the optional package or notification setting is absent. Conversely, an internet-facing server meeting the conditions should be treated as exposed to active exploitation. Microsoft and CSA both report exploitation in the wild; neither source provides a victim total.

What attackers did after gaining command execution

Microsoft observed intruders use the initial access to install web shells and establish additional access. The documented actions are observed techniques, not a checklist of steps that will appear on every compromised server.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Omada ER707-M2, Multi-Gigabit VPN Route
  • 【Flexible Port Configuration】1 2.5Gigabit WAN Port + 1 2.5Gigabit WAN/LAN Ports + 4 Gigabit WAN/LAN Port + 1 Gigabit SFP WAN/LAN Port + 1 USB 2.0 Port (Supports USB storage and LTE backup with LTE dongle) provide high-bandwidth aggregation connectivity.
  • 【High-Performace Network Capacity】Maximum number of concurrent sessions – 500,000. Maximum number of clients – 1000+.
  • 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
  • 【Highly Secure VPN】Supports up to 100× LAN-to-LAN IPsec, 66× OpenVPN, 60× L2TP, and 60× PPTP VPN connections.
  • 【5 Years Warranty】Backed by our 5-years warranty and free technical support from 6am to 6pm PST Monday to Fridays

JSP web shells and movement between mailbox nodes

In observed cases, attackers temporarily changed webroot permissions, built an encoded and compressed payload from fragments, and wrote JSP web shells into publicly reachable application directories. They removed the staging fragments after assembly. Microsoft found multiple shells in Jetty and mailboxd paths and reported copies being propagated to peer mailbox nodes.

Other access and persistence techniques

The report also describes attackers retrieving and executing payloads with wget or curl, launching background processes and opening interactive reverse shells. Observed persistence included cron jobs, systemd services and memory-backed execution. Microsoft also documented a privilege-escalation technique involving Zimbra service helpers and PAM configuration. The presence of one technique does not establish that the others were used.

Why the activity put authentication secrets at risk

The theft Microsoft describes went beyond individual mailbox passwords. Attackers ran zmlocalconfig -s to expose credentials used by services including LDAP, MySQL, Postfix, Amavis and replication. They then used recovered credentials in authenticated LDAP queries to retrieve sensitive attributes.

  • zimbraPreAuthKey, associated with pre-authentication.
  • zimbraAuthTokenKey, an authentication-token key.
  • zimbraTwoFactorAuthSecret, a two-factor authentication secret.

Microsoft says this credential-recovery and LDAP-query sequence appeared across multiple compromised Zimbra servers. A server with evidence of intrusion therefore needs a secrets assessment, not only a software update.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which Zimbra versions and configurations need attention

Zimbra identifies ZCS 10.1.20 as the release that fixes the SNMP monitoring command-injection issue. Its advisory list also includes later fixes in 10.1.21, so 10.1.20 is the stated fix release for this issue, not necessarily the newest release administrators should install. Follow Zimbra’s current release and deployment-specific upgrade instructions.

  • Prioritize investigation and upgrade: a server before 10.1.20 that has zimbra-snmp installed and SNMP notifications enabled, especially if internet-facing.
  • Reduce exposure while arranging an upgrade: if you cannot patch immediately, Microsoft’s interim measures are to uninstall optional zimbra-snmp, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts.
  • Do not treat configuration changes as a substitute for upgrading: Microsoft recommends upgrading affected deployments to 10.1.20 or later; CSA advises affected administrators to update immediately.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if a Zimbra server may be compromised

Apply the fix, but do not assume that patching removes access an attacker already established. Microsoft recommends scoping and containing affected servers, prioritizing reverse-shell alerts, checking for persistence such as unexpected systemd services, and rotating Zimbra authentication secrets when compromise is suspected.

Rank #4
UDPTCP Firewall, Intelligent Soft Routing Micro Appliance/Fanless Mini PC • Celeron N2840, 2 x RJ45(1000M), USB 3.0,HDMI,VGA, 4GB RAM 64GB mSATA SSD
  • 【◆Powerful Celeron N2840 Processor: N2840 Processor, 2 Cores 2 Threads, 1M Cache, Max Turbo Frequency 2.58 GHz, TDP 7.5 W. Compatible with OPNsense, Linux, Windows,ESXI, OpenWrt and other systems. Press "Delete" key to enter BIOS setup, supports Auto Power On, Wake On Lake, GPIO, PXE
  • 【◆1GbE LAN: Mini Router PC with 2*Realtek RTL8111H network card chip full UDE 1000M with filter connector.Soft Router can monitor network data, improve network security, powerful and widely used.
  • ◆DDR3L Memory & Large Storage Capacity: Firewall box computer with 1 x DDR3L SO-DIMM memory 1333/1600MHz, 1xMSATA3.0 SSD+1x2.5''SATA3.0 SSD/HDD.
  • ◆UHD Graphics & Dual Display: N2840 processor integrated UHD Graphics, HD and VGA dual display interfaces support 4K@60Hz.
  • ◆Rich interfaces: 2 x1000M Realtek RTL8111H-LAN,2 xUSB3.0, 4 xUSB2.0, HDMI,VGA,AUDIO supports data storage and system boot.
  1. Contain and scope. Investigate the affected server and potentially connected mailbox nodes. Look for reverse-shell activity, unexpected JSP files in publicly reachable application paths, unexplained cron jobs or systemd services, and changes involving Zimbra service helpers or PAM configuration. These are indicators drawn from Microsoft’s observed activity, not proof that every listed artifact will be present.
  2. Upgrade the vulnerable deployment. Install ZCS 10.1.20 or later, following Zimbra’s current release guidance for your deployment. If that cannot happen immediately, apply the interim exposure-reduction measures above while preparing the upgrade.
  3. Assess and rotate exposed secrets. Review credentials and authentication material accessible from the compromised service account, including service credentials and the LDAP attributes identified by Microsoft. Coordinate rotation with the services and applications that depend on those credentials so that access remains functional and compromised values are no longer trusted.
  4. Check the wider environment. Because Microsoft observed shells copied to peer mailbox nodes, include relevant cluster peers in scoping rather than limiting the investigation to the server where the initial alert appeared.

Microsoft’s report, Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570, was published September 30, 2026. CSA Singapore’s High-Severity Vulnerability in Zimbra Collaboration Suite was last updated October 2, 2026.

Best Value
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.