Zimbra CVE-2026-73570 attacks are actively targeting internet-facing mail servers, Microsoft warned on September 30. The vulnerability allows unauthenticated operating-system command injection through the optional zimbra-snmp component. Administrators should therefore verify the installed version, configuration and historical logs immediately instead of treating the patch as a routine update that can wait for the next maintenance window.
How the attack begins
According to Microsoft Incident Response, attackers send specially crafted SMTP messages to a system where SNMP notifications are enabled. The vulnerable component fails to handle certain values safely before passing them to operating-system tools. Hiding an administrative dashboard does not remove the exposure because the initial path uses the normal mail flow rather than a login to the administration interface.
Successful exploitation can lead to much more than a single command. Microsoft documented the deployment of web shells, reverse-shell access, privilege escalation and persistence. The impact may include reading email, stealing address books and secrets, changing forwarding rules and moving further through an organisation. A mail server is a particularly valuable target because it connects user identities, password resets and many business services.
Which versions need attention
Zimbra included a fix in version 10.1.20, released on July 20, while the CVE was publicly disclosed on August 13. Systems on older affected builds should move to 10.1.20 or a newer supported release. Teams should take a verified backup and record the current state before installation, but delay increases risk now that active exploitation has been confirmed.
If the update cannot be applied immediately, Microsoft recommends removing the zimbra-snmp package or disabling SNMP notifications when they are not required. That is a temporary mitigation, not a substitute for patching and investigation. SMTP and SNMP access should be restricted where the architecture permits, and outbound connections should be monitored. Merely changing a service port does not stop automated scanning or targeted attacks.

Zimbra CVE-2026-73570 attacks: evidence to inspect
Review should cover newly created JSP files in web directories, unusual systemd services, processes launched by the Zimbra account, changed cron jobs and connections to unfamiliar addresses. Logs need to be examined for the period before the patch was installed. If an attacker already established persistence, updating the software will not remove a web shell, a newly created account or stolen credentials.
Don’t miss this


Microsoft specifically advises rotating the zimbraPreAuthKey and other secrets available to the compromised system. Privileged passwords should be changed, active sessions revoked and automatic forwarding rules reviewed. Investigators should determine whether mailboxes, backups or address books were accessed or exported. When compromise is confirmed, an incident-response team should preserve forensic evidence before cleaning the machine.
Why smaller organisations are also exposed
Automated campaigns do not target only large companies. They search for any public service with a vulnerable configuration. A small mail installation can still contain reset links, contracts, invoices and employee identities, making it a useful entry point for fraud or wider network intrusion. Checking the version and optional component now is more valuable than waiting for endpoint protection to report a later-stage payload.
A practical order of work is to document the current state, create a verified backup, apply the update, inspect indicators of compromise and rotate secrets whenever intrusion is suspected. Centralised logging makes it harder for an attacker to erase the only copy of useful evidence. Organisations should also check standby servers and disaster-recovery images so that the same vulnerable component is not restored during recovery.
An administrator’s response checklist
The response to Zimbra CVE-2026-73570 attacks should not end with checking one version string. Every node in a cluster, backup site, proxy, mail store and optional package needs to be inventoried. Investigators should compare suspicious timestamps with account changes, forwarding rules and remote logins. If any reliable indicator of intrusion is present, evidence preservation must come before removal because exploitation may have exposed sensitive messages and long-lived secrets.
Rarely used administrator accounts, API tokens, certificates and integrations with archiving or antispam services also deserve review. If the mail server could query a corporate directory, the incident team must assess whether credentials or data from other systems were exposed. SajberSfera’s guide to preventing exposed cloud data provides related advice on inventory, access control and evidence preservation.
Key points
- CVE-2026-73570 is being actively exploited against internet-facing Zimbra servers.
- The fix is available in Zimbra 10.1.20 and newer supported releases.
- After suspected compromise, teams should investigate persistence and rotate keys and passwords.
Technical details and response guidance were verified against the official Microsoft Security Blog advisory.







