Security3 publishers2 min readPublished Updated
Crafted emails give attackers shells on Zimbra servers running SNMP notifications
Microsoft says attackers are using CVE-2026-73570 to run commands on Zimbra mail servers with one crafted email and no login. Zimbra shipped the fix in 10.1.20 on July 20, 24 days before disclosure, so anyone who waited for the advisory to patch was already late.
The Watch · Security desk

What happened
- The attack works only against internet-facing Zimbra servers with the optional zimbra-snmp package installed and SNMP notifications enabled, and no user has to open or click anything.
- Between July 28 and August 7, Microsoft watched two distinct scanning tools probe the injection point while the flaw was still undisclosed.
- After getting in, attackers deployed JSP web shells and reverse shells, escalated privileges, installed persistent remote-access tooling and ran payloads from memory.
- Attackers read email, collected authentication and mailbox data, packed it into archives and then transferred the archives.
- Microsoft found victim organizations in more than one region and more than one industry, with exploitation not confined to a single sector or geography.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Zimbra servers that never installed zimbra-snmp, or run with SNMP notifications off, are outside this bug. Where 10.1.20 cannot go in at once, removing the package or disabling notifications takes away a condition the exploit needs.
- cost The upgrade leaves in place any web shell, cron job or systemd unit planted before it. Any server exposed before patching needs a sweep of webroots and schedulers on every mailbox node, including peers of the one first hit.
- capability Successful probes called out from the mail server itself. Egress DNS and proxy logs showing that server contacting the listed callback domains, or sending a ZB73570 User-Agent, are evidence that commands ran there.
- exposure Taking authentication and mailbox data extends a server compromise to every user whose credentials and mail sat on it, so account resets and a mail-exposure review follow any confirmed hit.
The first probes Microsoft logged came eight days after Zimbra shipped the fix and 16 days before the CVE went public [1][2]. Both scanning tools used the same swatchdog-to-snmptrap route that later appeared in confirmed compromises [6].
The flaw sits in Zimbra's SNMP notification processing [1]. A crafted SMTP request carries shell metacharacters into the notification data [10]. When a service-state change sets off health monitoring, swatchdog places that attacker-controlled value inside an snmptrap shell command [10]. Whatever it contains runs with the privileges of the zimbra service account [3].
Early probes were built to confirm execution without delivering a payload [9]. Some ran local identity checks or dropped a small fingerprint script that showed both command execution and outside access to the server's webroot [9]. Others used curl, wget, ping and nslookup to reach one-off subdomains on oast[.]fun, oast[.]online, dnslog[.]pp[.]ua and requestrepo[.]com, plus campaign infrastructure under bypass[.]eu[.]org [7]. HTTP callbacks carried a ZB73570 User-Agent. DNS and ICMP callbacks used randomized subdomains [8].
In confirmed intrusions, attackers planted JSP web shells by changing webroot permissions, rebuilding an encoded, compressed payload from staged fragments, writing it into publicly reachable application directories and deleting the fragments [15]. Shells went onto both Jetty and mailboxd paths, with extra copies on peer mailbox nodes [17]. Other chains used cron, systemd or memfd_create for recurring or memory-backed execution [16].
Two distinct scanning tools, campaign infrastructure and automated payload delivery running beside hands-on-keyboard sessions describe an organized, repeated operation [6][7][13]. Microsoft's attack-chain diagram merges behavior from several confirmed compromises. No single host necessarily showed every stage [18].
What to watch
- A public proof of concept for CVE-2026-73570 would put the injection path within reach of operators beyond the two scanning tools Microsoft tracked.
- Attribution of the activity to a named group would show whether one crew or several are working the same bug.
- A count of affected organizations from Microsoft would size a campaign currently described only as spanning more than one region and industry.