2026-08-20HIGHexploitedFixed on 20 July, identified on 13 August, probed from 28 July: a CVE-keyed patch process never saw this one coming
Zimbra Collaboration, pre-authentication command injection in SNMP notification processing reaching OS command execution as the Zimbra user; fixed in 10.1.20 (21 July 2026), CVE published 13 August, ENISA records exploitation from 2026-08-18.
cve · CVE-2026-73570
Coverage
1
first 2026-08-20 → last 2026-10-02
Latest activity
2026-10-02
Fixed on 20 July, identified on 13 August, probed from 28 July: a CVE-keyed patch process never saw this one…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education, telco · regions: europe
Sources cited
9
7 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-73570, newest first. Check the date before acting on an older one.
- Upgrade every Zimbra Collaboration host to 10.1.21 (10.1.20 is the minimum for CVE-2026-73570); where the upgrade cannot happen at once, remove the zimbra-snmp package or disable SNMP notifications and restrict SNMP and SMTP to trusted hosts.2026-08-20CVE-2026-73570
- On every host that ran a build before 10.1.20 with SNMP notifications enabled at any time since 2026-07-28, upgrading is not enough: rotate all domain zimbraPreAuthKey values and run the compromise check described in the body on every mailbox node.2026-08-20CVE-2026-73570
Defender insights
What each entry about CVE-2026-73570 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (18 across 10 tactics)
18 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissanceActive Scanning: Vulnerability Scanning
- Initial AccessExploit Public-Facing Application
- ExecutionScheduled Task/Job: Cron · Command and Scripting Interpreter: Unix Shell
- PersistenceScheduled Task/Job: Cron · Server Software Component: Web Shell · Create or Modify System Process: Systemd Service
- Privilege EscalationScheduled Task/Job: Cron · Create or Modify System Process: Systemd Service · Abuse Elevation Control Mechanism: Sudo and Sudo Caching
- StealthMasquerading: Match Legitimate Resource Name or Location · Indicator Removal: Timestomp · Reflective Code Loading
- Credential AccessUnsecured Credentials: Credentials In Files
- Lateral MovementRemote Services: SSH · Lateral Tool Transfer
- CollectionEmail Collection: Local Email Collection · Archive Collected Data: Archive via Utility
- Command and ControlApplication Layer Protocol: Web Protocols · Proxy · Ingress Tool Transfer
Reconnaissance TA0043
T1595.002Active Scanning: Vulnerability Scanning×1
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Execution TA0002
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Persistence TA0003
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Privilege Escalation TA0004
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching×1
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Stealth TA0005
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1070.006Indicator Removal: Timestomp×1
Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Credential Access TA0006
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Lateral Movement TA0008
T1021.004Remote Services: SSH×1
Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1570Lateral Tool Transfer×1
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Collection TA0009
T1114.001Email Collection: Local Email Collection×1
Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1560.001Archive Collected Data: Archive via Utility×1
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1090Proxy×1
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗
Entries about Zimbra Collaboration, pre-authentication command injection in SNMP notification processing reaching OS command execution as the Zimbra user; fixed in 10.1.20 (21 July 2026), CVE published 13 August, ENISA records exploitation from 2026-08-18. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- wiki.zimbra.com3 (33%)
- cert.ssi.gouv.fr1 (11%)
- cisa.gov1 (11%)
- euvd.enisa.europa.eu1 (11%)
- microsoft.com1 (11%)
- security-hub.ncsc.admin.ch1 (11%)
- thehackernews.com1 (11%)
External references
All cited sources (9)
- cert.ssi.gouv.frprimaryCERT-FR (ANSSI)https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1041/
- cisa.govCISA Known Exploited Vulnerabilities cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- euvd.enisa.europa.euENISA EU Vulnerability Databasehttps://euvd.enisa.europa.eu/vulnerability/CVE-2026-73570
- microsoft.comMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
- security-hub.ncsc.admin.chNCSC Switzerland, Cyber Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/13022
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html
- wiki.zimbra.comZimbra (10.1.20 release notes)https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20
- wiki.zimbra.comZimbra (10.1.21 release notes)https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.21
- wiki.zimbra.comZimbra (vendor security advisories)https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories