Microsoft says attackers exploited an unauthenticated command-injection flaw in internet-facing Zimbra mail servers. The practical check is specific: the vulnerable path requires the optional zimbra-snmp package to be installed and SNMP notifications to be enabled; Microsoft says Zimbra 10.1.20 contains the fix.
Watch Desk analysis
What happened
In a report published on 30 September, Microsoft describes exploitation of CVE-2026-73570. It says specially crafted email could trigger command execution through Zimbra’s SNMP notification processing, without authentication or user interaction. Microsoft reports seeing the activity across organisations in multiple regions and industries.
Microsoft says scanning activity appeared between 28 July and 7 August, after the fix was released on 20 July but before the vulnerability was publicly disclosed on 13 August. In investigated compromises, it observed attackers establish web shells and remote access, escalate privileges, and collect mail and authentication data. Microsoft says the report combines behaviour from multiple confirmed compromises, not one sequence that necessarily occurred on every affected server.
Who is affected
- Check the vulnerable configuration
The reported attack path requires both the optional zimbra-snmp package and enabled SNMP notifications on an internet-facing Zimbra server. - Check the fix level
Microsoft identifies Zimbra 10.1.20, released on 20 July, as containing the remediation.
Why it matters
This is not a warning about a theoretical flaw alone: Microsoft says it observed exploitation and post-compromise activity. The reported route needs no login or user action, while the attackers’ activity could extend from command execution to privileged access and mailbox data collection.
Our read
For Zimbra operators, verify whether the affected package and setting are present, then confirm the server is on a remediated version. Microsoft’s account is detailed threat-intelligence reporting; its observations should not be mistaken for proof that every affected server saw every listed technique. Still, “we’ll look at it next week” is not an especially charming incident-response plan.
What to watch
- Whether Zimbra publishes further technical guidance or updates the affected-version information.
- Whether Microsoft or other responders report additional affected environments or exploitation activity.
- Whether operators disclose compromises linked to this vulnerability.
Discussion spark: Should internet-facing mail servers disable optional services they do not use by default, or should operators bear the burden of finding and securing them?
Sources and evidence
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 – Microsoft (30 September 2026, 14:00 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.