CVE-2026-73570, Zimbra Collaboration: a pre-auth command injection patched without a CVE in July is exploited, with probing before disclosure and root escalation, secret theft and cluster-wide movement observed
Fixed on 20 July, identified on 13 August, probed from 28 July: a CVE-keyed patch process never saw this one coming
Defender actions
- Upgrade every Zimbra Collaboration host to 10.1.21 (10.1.20 is the minimum for CVE-2026-73570); where the upgrade cannot happen at once, remove the zimbra-snmp package or disable SNMP notifications and restrict SNMP and SMTP to trusted hosts.
- On every host that ran a build before 10.1.20 with SNMP notifications enabled at any time since 2026-07-28, upgrading is not enough: rotate all domain zimbraPreAuthKey values and run the compromise check described in the body on every mailbox node.
Analysis
Zimbra's own security-advisory table records the fix for CVE-2026-73570 as "Fixed a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled", shipped in release 10.1.20 (Zimbra, 2026-08-13). That release went out on 20 July 2026 (Zimbra, 2026-07-20) carrying nine fixes, and at the time none of them had been flagged as actively exploited; the vendor's stated position was that "in line with industry best practices, information disclosure is limited for security vulnerability fixes" (The Hacker News, 2026-07-21). The identifier arrived nearly four weeks later, on 13 August, and the ENISA record describes the mechanism in full: because untrusted input is not properly sanitised during SNMP notification processing, "an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user" (ENISA EU Vulnerability Database, 2026-08-13). ENISA scores it 8.9 with high attack complexity (ENISA EU Vulnerability Database, 2026-08-13), and the flaw applies only to deployments where the optional zimbra-snmp package is installed and SNMP notifications are enabled.
On 19 August CERT-FR issued its own advisory for the Zimbra bulletin and stated plainly that ENISA records CVE-2026-73570 as actively exploited (CERT-FR, 2026-08-19). ENISA's record lists it in the EU KEV catalog from 18 August (ENISA EU Vulnerability Database, 2026-08-13). What makes this worth an out-of-band look rather than a place in the next patch window is the sequence rather than the score: the code was fixed in July with no identifier attached, so an estate that drives its patching from CVE feeds, scanner signatures or an SBOM pipeline had nothing to match against for almost four weeks, and the flaw only became visible to those processes five days before it was recorded as exploited. Anyone who upgraded to 10.1.20 in July for unrelated reasons is already covered and does not know it; anyone who deferred is now unpatched against a flaw with a published exploitation status.
The behaviour to look for follows from the mechanism. Command injection at the point where a notification is formatted means the observable is a mail-server process tree spawning something it has no business spawning: an interpreter or utility process whose parent is the Zimbra mail or notification component, running under the zimbra service account rather than under a scheduled administrative task. In process-execution telemetry with parent lineage, that lineage is the signal: SNMP notification handling legitimately produces notification traffic, not shells, and Microsoft's hunting logic looks for a shell created by Perl running a generated swatchdog script, with an injection signature that is a legitimate snmptrap invocation immediately followed by shell metacharacters and a wget or curl call, wrapped in a trailing comment character that swallows the remaining legitimate arguments (Microsoft Threat Intelligence, 2026-09-30). On the network side, an outbound connection initiated by the zimbra account immediately after inbound SMTP is the same event viewed from the other end. Triage: Zimbra hosts do legitimately run monitoring integrations under the same account, so process identity alone will not separate them; the discriminators are the parent process being the notification path rather than a cron or monitoring agent, and the absence of a matching operator change record for a host that has no history of spawning interpreters at all.
Cited evidence
ENISA indicates that vulnerability CVE-2026-73570 is being actively exploited. (translated from French)
Fixed a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.
none of the identified vulnerabilities have been flagged as actively exploited
Between July 28 and August 7, after a fix became available on July 20 but before public disclosure on August 13, Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point.
Rotate all domain zimbraPreAuthKey values and review systemd units for unexpected ownership, enablement, or timestamp changes
Updates1
Microsoft Threat Intelligence published first-hand analysis on 2026-09-30 of CVE-2026-73570 exploitation in more than one region and industry, naming no actor (Microsoft Threat Intelligence, 2026-09-30). It saw two out-of-band scanning tools probing the injection point between 2026-07-28 and 2026-08-07, after the fix and before the 2026-08-13 disclosure (Microsoft Threat Intelligence, 2026-09-30). CISA's KEV catalog lists the CVE, added 2026-08-21 (CISA KEV, 2026-08-21).
After command execution as the zimbra account, Microsoft observed, across its cases and not necessarily on every host, JSP web shells written to publicly served directories after temporarily opening write permission, with copies on peer mailbox nodes, and reverse shells built from a named pipe and openssl s_client; a privilege escalation that used a symlinked log file to take ownership of the sudo PAM configuration, added a pam_exec hook and created a NOPASSWD sudoers entry for the zimbra account; a systemd unit named like a Zimbra logging component with timestamps matched to existing services; theft of Zimbra's service credentials with zmlocalconfig -s, followed by authenticated LDAP queries for the pre-authentication key, the auth-token key and the two-factor secret attribute; and SSH and rsync movement across the cluster with Zimbra's own SSH identity (Microsoft Threat Intelligence, 2026-09-30). Microsoft's remediation is to upgrade to 10.1.20 or later, remove the zimbra-snmp package or disable SNMP notifications and restrict SNMP and SMTP to trusted hosts, rotate all domain zimbraPreAuthKey values, review systemd units, and hunt for JSP files on every mailbox node (Microsoft Threat Intelligence, 2026-09-30).
Zimbra's 10.1.21 release of 2026-09-24 also fixes unauthenticated prediction of password-recovery codes that could reset a user's password, WebDAV acceptance of pre-MFA tokens, and OnlyOffice-integration flaws including file write to remote code execution (Zimbra, 2026-09-24); the table lists no CVE or score for the recovery-code and WebDAV fixes (Zimbra, 2026-08-13), and NCSC Switzerland published an advisory for the release on 2026-10-01 with exploitation status unknown (NCSC Switzerland, 2026-10-01).
Sources9
Revision history
- Published 2026-08-20T0409Z-intel
- Update 2026-10-02T0404Z-intel
Microsoft Threat Intelligence published first-hand analysis of confirmed intrusions: probing of the injection point from 2026-07-28, before the 2026-08-13 disclosure, then web shells, root escalation, theft of Zimbra's authentication keys and cluster-wide movement, with the injection signature to hunt for. The 10.1.21 release, which also fixes unauthenticated password-recovery code prediction, and NCSC-CH's advisory of 2026-10-01 are added. CISA's KEV listing of 2026-08-21, not recorded before, is added; the 10.1.20 release date is corrected to 2026-07-20, the EPSS score is refreshed to 0.117 (FIRST, 2026-10-01), ENISA's 18 August date is its EU KEV listing, and the actions now ask for a compromise check as well as the upgrade.
Changed: title headline summary tags techniques cves sources evidence sourcing_note classification actions update_of body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.