Security · October 3, 2026

Also published in Norsk

Microsoft warns of active exploitation of Zimbra zero-day vulnerability

Floating metallic cubes in shades of blue and purple with reflective surfaces
Milad Fakurian / Unsplash

Microsoft Threat Intelligence has published a detailed warning regarding a critical zero-day vulnerability identified as CVE-2026-73570. This flaw affects the Zimbra Collaboration Suite, a platform widely used in corporate environments for electronic mail, group calendars, and document and task management. The advisory highlights that the vulnerability is being actively exploited by threat actors to deploy webshells and compromise organizational infrastructure.

The security issue resides in the Simple Network Management Protocol notification path within the Zimbra package. It is classified as an unauthenticated operating system command injection vulnerability. Experts indicate that the flaw can be triggered by specially formulated SMTP requests sent to publicly accessible mail servers. This exploitation is possible when the zimbra-snmp package is installed and SNMP notifications are enabled. In such scenarios, attackers gain the ability to execute commands remotely on the system with the privileges of the Zimbra service account, without requiring any interaction from the user.

Telemetry data collected by Microsoft confirms that the threat is not theoretical but has been actively used by hacking groups for espionage and data exfiltration. Cybercriminal activity has focused on breaching perimeter security and gaining persistent access to corporate resources. This was achieved by stealing confidential authentication secrets, pre-authorization keys, and session tokens. During reconnaissance and operational phases, the deployment of numerous JSP webshells was observed in Jetty application paths and mailboxd, as well as on peer mailbox nodes. This attack architecture allowed intruders to maintain alternative access paths while minimizing the risk of detection by standard monitoring tools. In some cases, intruders modified public directory permissions to deploy malicious code and then restored the original system settings, effectively erasing traces during basic permission audits.

Effective defense against these attack vectors requires IT departments to implement a comprehensive risk mitigation strategy. The software vendor has released an official security patch in version 10.1.20, and its implementation is strongly recommended by market experts. In situations where immediate system updates are not possible, administrators are advised to completely uninstall the unnecessary zimbra-snmp package and strictly limit network access to SNMP and SMTP services. Additionally, security teams should utilize advanced Extended Detection and Response tools to perform detailed log correlations. This process aims to identify unusual script invocations and unauthorized modifications in system file structures, enabling the early detection of potential intruder presence within the enterprise network.