Microsoft Threat Intelligence reported that attackers were exploiting a critical vulnerability in Zimbra Collaboration Suite, tracked as CVE-2026-73570, before it was publicly disclosed. The flaw is an unauthenticated command injection vulnerability that affects servers running Zimbra's optional SNMP monitoring package with notifications enabled. An attacker can send a specially crafted email to a vulnerable, internet-facing server to execute commands without needing a password or tricking a user into clicking a malicious link.
Zimbra fixed the flaw in version 10.1.20 on July 20, but the vulnerability was not publicly disclosed until August 13. Microsoft spotted two different scanning tools probing the same part of Zimbra that would later be used in attacks, starting on July 28. The initial activity appeared focused on identifying vulnerable servers and testing whether the flaw could be exploited. Attackers used common network utilities to confirm command execution by making compromised systems call back to infrastructure they controlled.
Once attackers confirmed a server was exploitable, they escalated their activities. Microsoft's investigation found attackers deploying web shells and reverse shells, escalating privileges, installing tools for persistent remote access, and running malicious code directly in memory. In some cases, attackers temporarily changed permissions on public directories to plant web shells, then restored the original settings to avoid detection.
The intruders also explored the wider Zimbra environments, identifying other mail servers and looking for trusted connections, such as existing SSH relationships, to move laterally between systems. On at least one compromised machine, attackers achieved root access and set up persistent command execution without requiring a password.
Mailbox data was a clear target. Attackers hunted for Zimbra credentials and authentication secrets. Microsoft uncovered a malicious tool built to extract service account credentials and pull mailbox information from Zimbra's databases. In another incident, attackers bundled recent mailbox backups into an archive and attempted to exfiltrate them to Azure Blob Storage using Microsoft's AzCopy utility. Microsoft could not confirm from the available evidence whether the transfer was successful.
Microsoft observed affected organizations across multiple regions and industries, with attacks ranging from automated exploitation to more deliberate hands-on-keyboard activity. The company has not attributed the activity to any specific threat actor.
Zimbra administrators still running versions earlier than 10.1.20 are urged to update immediately. Those unable to patch can reduce exposure by removing the optional SNMP package or disabling SNMP notifications. The early exploitation of this bug highlights the risk of vulnerabilities being discovered and exploited before public disclosure, even after a vendor has issued a fix.