Skip to content
Field reportTI-2026-0439

A mail server bug probed before disclosure

Microsoft tracked exploitation of a Zimbra command injection and found scanning for it in the window between the fix and the public CVE.

2 minThreat IntelligenceFresh · 30 Sept

Microsoft Threat Intelligence has published its tracking of CVE-2026-73570, an unauthenticated command injection in the SNMP notification path of Zimbra Collaboration Suite. A crafted SMTP request can carry shell metacharacters into SNMP notification processing, where they execute with the privileges of the zimbra service account. No authentication and no user interaction are required, but the optional zimbra-snmp package must be installed and notifications enabled.

The window nobody watches

The timeline is the part worth keeping. Zimbra 10.1.20, which contains the fix, was released on 20 July 2026; the CVE was publicly disclosed on 13 August. Between 28 July and 7 August, after the fix existed but before anyone was told what it was for, Microsoft observed two distinct out-of-band scanning tools probing the same injection point later used in attacks.

Those probes were built to confirm execution without delivering anything. They used ordinary commands to call back to unique subdomains on public interaction services over HTTP, DNS and ICMP, with a request header naming the CVE, or dropped a small fingerprinting script, demonstrating both command execution and outside access to the server's web root. A patch diff is a disclosure of its own, and this is what that looks like in telemetry.

After exploitation the activity was conventional and thorough: JSP web shells written into publicly reachable application directories by reassembling encoded fragments and then deleting them, reverse shells, privilege escalation, and persistence through cron, systemd or memory-backed execution. Attackers read email and collected authentication and mailbox data, creating archives and moving them off the host. Microsoft saw both automated delivery and hands-on operators, across more than one region and industry.

For defenders the practical check is narrow: whether the optional SNMP package is installed at all, and whether anything touched the web root between late July and mid-August. The mitigating detail is that this configuration is not the default, so the exposed population is smaller than the product's install base.

Retold from Microsoft Security. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined