Attackers Probed Zimbra's SNMP Flaw Eight Days After Its Patch
Security / news
Attackers Probed Zimbra's SNMP Flaw Eight Days After Its Patch
Microsoft's Sept. 30 write-up of CVE-2026-73570 dates the first reconnaissance to July 28, then traces web shells, root escalation and mailbox theft on unpatched servers.

An unauthenticated attacker who can send mail to an internet-facing Zimbra server can run commands as the zimbra user, provided the optional zimbra-snmp package is installed and SNMP notifications are on. Microsoft's Sept. 30 analysis of CVE-2026-73570 says attackers have used that foothold to reach root and copy mailboxes. Zimbra Collaboration 10.1.20 contains the fix.
The flaw sits in the SNMP notification path. Crafted SMTP content puts shell metacharacters into the snmptrap command that swatchdog runs, according to Microsoft, and the command executes as the service account with no login and no user interaction.
Timeline from patch to write-up
The dates come from Microsoft, apart from the federal deadline, which The Hacker News reports.
- July 20, 2026: Zimbra releases 10.1.20 with the fix.
- July 28 to Aug. 7: Microsoft observes reconnaissance against the injection path; The Hacker News says two scanning tools were responsible.
- Aug. 13: public disclosure.
- Aug. 24: CISA's deadline for federal agencies to fix the flaw, per The Hacker News.
- Sept. 30: Microsoft publishes its findings.
The ordering matters more than the score. The first probing began eight days after the patch and 16 days before disclosure, so an operator who tracked advisories instead of release notes ran a vulnerable build while scanners were already testing it.
What the observed attack chain did
Microsoft's write-up follows the intrusion in stages:
| Stage | Observed activity |
|---|---|
| Initial access | Crafted SMTP triggers shell metacharacters in the snmptrap call, running as zimbra |
| Persistence | JSP web shells under Jetty and mailboxd paths; a systemd unit named zimlog.service with altered timestamps |
| Privilege escalation | A symbolic link into the PAM configuration directory, combined with abuse of zmmailboxdmgr, to gain sudo |
| Data theft | Credentials read with zmlocalconfig -s; authentication keys and pre-auth material pulled from LDAP; mailbox archives staged |
The Hacker News adds details from the same research: database tables named mailbox, mailbox_metadata and mobile_devices were targeted, and in one instance mailbox data was archived to /opt/zimbra/final.tar.gz before an attempted transfer with AzCopy. It also lists cron jobs, SSH authorized-key changes and memory-backed execution through memfd_create as persistence.
The score understates what a compromised server loses
The Hacker News gives the flaw a CVSS score of 8.9. The score understates the outcome on servers where the package is present, because the chain Microsoft saw ends at root and at every mailbox on the host. It overstates the exposure across Zimbra as a whole, because zimbra-snmp is an optional package.

What to do on a Zimbra server
Upgrade to 10.1.20 or later. If you cannot, remove zimbra-snmp or disable SNMP notifications, which closes the path Microsoft describes. Microsoft's guidance then points at the aftermath: rotate the zimbraPreAuthKey values and other Zimbra authentication secrets, inspect systemd units for odd ownership or timestamps, and hunt for JSP files in application directories on every mailbox node.
Microsoft says Defender detects the activity through Perl launching a shell that contains snmptrap commands. Microsoft does not say how many servers were compromised, so patching alone leaves the question of whether a server was already taken unanswered. CISA's list has carried AI-gateway flaws before, and Microsoft has been on the other side of a disclosure in its own Titan token flaw. Microsoft's Zimbra write-up gives no count of compromised hosts, and that number is the next thing to look for.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.