A patched Zimbra Collaboration Suite (ZCS) flaw is being exploited in the wild to run operating-system commands, install web shells and pull email archives and credentials out of vulnerable mail servers, Microsoft warned on Wednesday.
THE VULNERABILITY. CVE-2026-73570 allows remote, unauthenticated attackers to execute OS commands through a crafted email. The path runs through ZCS's SNMP notification handling, and exploitation requires two conditions: the optional zimbra-snmp package installed and SNMP notifications enabled. "An attacker can send a specially crafted SMTP request that introduces untrusted input into SNMP notification processing," Microsoft wrote. "If the input is not sufficiently sanitized, embedded shell commands can execute with the privileges of the zimbra service account."
TIMELINE. Zimbra maintainer Synacor issued a patch on July 20 but did not disclose the vulnerability for more than three weeks afterwards. From July 28 to August 7, Microsoft detected two distinct scanning tools probing the internet for vulnerable endpoints. The attackers first validated their exploit with HTTP, DNS, ICMP and out-of-band identity checks to confirm commands executed without actually compromising the servers, then began installing payloads.
WHAT THE INTRUDERS DID. Microsoft observed JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling and memory-backed execution. Attackers accessed email, created archives and transferred data, and collected authentication and mailbox data, in a mix of automated payload delivery and hands-on-keyboard operations. Affected organisations spanned more than one region and industry, and exploitation was not limited to a single sector or geography. Microsoft said it could not verify whether exfiltration succeeded, and offered no attribution.
EXPOSURE. The Shadowserver Foundation said last week that its scans found 274 separate compromised instances. The population of reachable servers has fallen sharply — from roughly 19,000 in the week after the patch, to about 12,000, to around 10,000 now — which shrinks the target pool but also suggests slow patching.
WHAT TO DO. Anyone maintaining ZCS should be running version 10.1.20 or later, and should treat email archives and service-account credentials on previously unpatched hosts as potentially compromised rather than merely exposed.




