Vulnerabilities · 2h ago

Zimbra Flaw Opened Mail Servers to Silent Intrusion

Microsoft and CERT Polska tied active exploitation of Zimbra Collaboration Suite CVE-2026-73570 to web shells, mailbox access, persistence, and archive transfer after Zimbra shipped version 10.1.20 in July 2026. The flaw only exposes servers where the optional zimbra-snmp package is installed and SNMP notifications are enabled, which makes a subset of mail servers unauthenticated remote-execution targets.

In plain terms, a specially crafted SMTP message can reach the vulnerable path without a login, and Zimbra then runs attacker-controlled commands because the SNMP-related add-on opens a trusted route. Microsoft said the observed follow-on activity included JSP web shells, reverse shells, privilege escalation, and access to email, authentication data, and mail archives.

The important map point is that patching removes the vulnerable code but does not erase what may already be on the host. If your Zimbra deployment used that optional package, the exposure sits in both the mail server and whatever secrets or mailbox data were already taken before the fix.

CVE-2026-73570

NVD KEV

Known exploited · CISA KEV

CVSS 8.9 HIGH: a remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. EPSS 12% (96th percentile).

CISA federal remediation date Aug 24 · date passed

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-30

Editions

Related stories