Overview
- Zimbra issued a patch on July 20, 2026, for CVE-2026-73570, a command-injection bug that lets attackers run OS commands when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
- Microsoft published detailed telemetry on September 30, 2026, showing early scans between July 28 and August 7 that validated command execution before operators delivered web shells and hands-on access.
- Observed attacker actions included deploying JSP web shells and reverse shells, escalating privileges, harvesting Zimbra service-account credentials, and exporting mailbox-related database tables.
- At least one operation staged mailbox backups into a local archive and invoked AzCopy with a supplied Azure SAS URL to try to move data to cloud storage, though Microsoft could not confirm the transfer completed.
- Security teams and CISA advise immediate patching or removal of zimbra-snmp, disabling SNMP notifications, rotating Zimbra secrets, restricting SNMP/SMTP access, and hunting for web shells and persistence artifacts.