Hackers Exploited Zimbra Mail Server Flaw Weeks Before Public Warning
Microsoft Threat Intelligence has revealed that attackers were actively exploiting a critical Zimbra mail server vulnerability, tracked as CVE-2026-73570, before it even had an official disclosure date. The flaw allows unauthenticated command injection, meaning an attacker can send a specially crafted email to a vulnerable internet-facing server and potentially execute commands, no stolen password or phishing click required. The bug only affects Zimbra servers running the optional SNMP monitoring package with notifications enabled. Zimbra patched the issue on July 20 in version 10.1.20, but the vulnerability was not publicly disclosed until August 13, leaving a window where attackers were already probing for targets.
Microsoft observed scanning activity between July 28 and August 7 that later matched techniques used in real attacks. Once attackers confirmed a server was vulnerable, they moved quickly: deploying web shells and reverse shells, escalating privileges, installing tools for persistent remote access, and running malicious code in memory. Some attackers even restored file permissions after planting web shells in an apparent attempt to cover their tracks.
The intrusions did not stop at a single server. Attackers explored connected Zimbra environments, using existing trusted connections such as SSH relationships to move to other mail servers. On at least one compromised machine, attackers escalated to root access and set up persistent, password-free command execution with the highest level of privilege.