Zimbra mail server flaw exploited in the wild, Microsoft warns after weeks of quiet attacks

Microsoft Threat Intelligence says attackers used a specially crafted email to hijack Zimbra Collaboration Suite mail servers, drop web shells and steal mailbox data, before the flaw was patched.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server rack in a data centre, blue and amber status LEDs glowing, one server unit slightly pull
Share

Key points

  • Microsoft Threat Intelligence confirmed on 30 September 2026 that attackers used a single crafted email to break into Zimbra mail servers, without needing a password or any action from a user.
  • The flaw, CVE-2026-73570, sits in an optional add-on called zimbra-snmp and was fixed in Zimbra Collaboration Suite version 10.1.20.
  • The US Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalogue, giving federal agencies a tight window to patch.
  • After breaking in, the attackers installed hidden back doors, stole login details and copied mailboxes, working both automatically and by hand.
  • Microsoft says victims spanned more than one country and industry, so this was not a targeted campaign against a single sector.

A mail server that reads its own incoming mail as commands is a bad day for everyone involved. That's essentially what happened here.

Microsoft Threat Intelligence published details on 30 September 2026 of attacks against internet-facing Zimbra Collaboration Suite servers, a widely used email and calendar platform popular with governments and mid-sized businesses. We first covered this CVE on 20 August 2026, when Poland's CERT warned of active exploitation. The flaw was patched weeks before Microsoft went public.

The bug lives in zimbra-snmp, an optional Zimbra component that sends out network alerts using SNMP (Simple Network Management Protocol, a standard for monitoring devices). When those alerts are switched on, an attacker can send an email crafted in a specific way, and parts of that email get run as commands on the server itself. No password needed. The server does it on its own.

What did the attackers actually do?

Once inside, they made themselves at home. Microsoft saw web shells written in JSP (small hidden control panels dropped onto the server), reverse shells that call back out to the attacker, tools that gained higher privileges, and code that ran only in memory to avoid leaving files on disk. That last technique echoes what we reported on 17 September 2026, when a Linux rootkit hid inside F5 BIG-IP devices and ran entirely from memory.

From there the operators grabbed credentials and packaged entire mailboxes to send elsewhere. Some activity was automated; a human at a keyboard handled the rest.

Which versions are affected and what should admins do?

Anything running Zimbra Collaboration Suite before version 10.1.20 with zimbra-snmp installed and SNMP notifications turned on is exposed. The fix is to update to 10.1.20 or later. Where immediate patching isn't possible, disabling SNMP notifications removes the attack path entirely.

Item Detail
CVE ID CVE-2026-73570
Severity 8.9 (High)
Fixed in Zimbra Collaboration Suite 10.1.20
Microsoft public writeup 30 September 2026

Should ordinary email users worry?

Probably not directly, but indirectly, yes. If your employer or university ran Zimbra and didn't patch quickly, your work emails and password reset links may have passed through a server the attackers controlled.

Treat any surprise password reset email with suspicion, change passwords on accounts that use your work address for recovery, and turn on two-step login where you can.

The Rufus read

Strip away the AI-era vocabulary and this is a classic command injection, the same bug class that has haunted web forms for twenty years, just wearing an SMTP hat. The three-day CISA federal deadline told you Washington already knew this was being used in anger; Microsoft's writeup six weeks later fills in what the attackers did next. If you run Zimbra and still haven't patched, assume you're already someone else's mail server.

© 2026 Threat Vectr