Critical Zimbra Flaw Exploited to Steal Emails Weeks Before the Bug Was Publicly Disclosed
Attackers used Zimbra flaw CVE-2026-73570 to plant web shells and reach mailboxes while the bug was patched but not yet disclosed. Upgrade to 10.1.20 now.

Attackers spent the summer breaking into Zimbra mail servers through a critical flaw that most defenders did not know existed. The bug, tracked as CVE-2026-73570 with a CVSS score of 8.9, let hackers deploy web shells and reach mailbox data and credentials, Microsoft warned.
The worst part is the gap. Zimbra's maintainer, Synacor, shipped a fix on July 20 in version 10.1.20 but did not disclose the vulnerability for more than three weeks. Attackers were already scanning for it during that silence.
An email that runs commands
The flaw is an unauthenticated operating system command injection. A crafted SMTP request, essentially a malicious email, can inject shell commands into Zimbra's SNMP notification processing. Those commands then run as the zimbra service account.
There is a condition. The server must have the optional zimbra-snmp package installed with SNMP notifications enabled. That narrows the exposure, but it also means administrators who turned on monitoring to keep their systems healthy may have handed attackers a way in.
Scanning during the silent window
Between July 28 and August 7, Microsoft detected two distinct scanning tools probing the internet for vulnerable Zimbra endpoints. That window falls squarely inside the period when a patch existed but almost nobody had a reason to rush it.
The attackers were methodical. They first confirmed targets with HTTP, DNS, ICMP and out-of-band checks. Then they installed JSP web shells and reverse shells, escalated privileges, planted persistent remote-access tooling, and used memory-backed execution to leave fewer traces on disk.
Once inside, they went for the mail. They accessed email, collected authentication and mailbox data, and created archives staged for transfer. Microsoft saw victims in more than one region and industry, though it said it could not verify successful exfiltration in the cases it investigated and offered no attribution.
Hundreds of servers already compromised
The Shadowserver Foundation reported 274 compromised Zimbra instances in recent scans. Exposure is shrinking but still large: about 19,000 instances were visible in the week after the patch, falling to roughly 12,000 and now about 10,000 tracked.
Patching alone will not clean up those 274 servers. Web shells and persistent backdoors survive an upgrade, so any organization that ran a vulnerable build with SNMP notifications enabled this summer needs to hunt for implants, not just install 10.1.20.
Why quiet patches backfire
Silent patching is sometimes defended as a way to give customers a head start before attackers learn the details. Here it did the opposite. Someone figured out the bug anyway, while administrators had no advisory telling them the update was urgent.
Email servers are among the most valuable targets on any network because they hold contracts, password resets and private conversations. Mail data has featured in some of the year's biggest incidents, including the Pentagon DMDC breach affecting 3 million people, and attackers keep finding ways to exploit flaws before defenders see them, as with the recent Apple CoreGraphics zero-day.
Anyone running Zimbra Collaboration Suite should be on version 10.1.20 or later, and should check whether zimbra-snmp was ever enabled. If it was, the server may have been open for weeks before anyone said a word.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free