Microsoft detects hackers exploiting critical Zimbra bug before public disclosure

Attackers probed vulnerable mail servers for two weeks after patch but before details were known, stealing credentials and accessing mailboxes

By LineZotpaper
Published
Read Time3 min
Microsoft Threat Intelligence has detected attackers actively exploiting a critical unauthenticated command injection vulnerability in Zimbra Collaboration Suite, CVE-2026-73570, weeks before the flaw was publicly disclosed. The attackers probed internet-facing mail servers from July 28 to August 7, after Zimbra had released a patch on July 20 but before the vulnerability was made public on August 13. Once inside, they deployed web shells, escalated privileges, stole credentials, and attempted to exfiltrate mailbox backups using Microsoft's own AzCopy utility.

Microsoft Threat Intelligence reported that attackers were exploiting a critical vulnerability in Zimbra Collaboration Suite, tracked as CVE-2026-73570, before it was publicly disclosed. The flaw is an unauthenticated command injection vulnerability that affects servers running Zimbra's optional SNMP monitoring package with notifications enabled. An attacker can send a specially crafted email to a vulnerable, internet-facing server to execute commands without needing a password or tricking a user into clicking a malicious link.

Zimbra fixed the flaw in version 10.1.20 on July 20, but the vulnerability was not publicly disclosed until August 13. Microsoft spotted two different scanning tools probing the same part of Zimbra that would later be used in attacks, starting on July 28. The initial activity appeared focused on identifying vulnerable servers and testing whether the flaw could be exploited. Attackers used common network utilities to confirm command execution by making compromised systems call back to infrastructure they controlled.

Once attackers confirmed a server was exploitable, they escalated their activities. Microsoft's investigation found attackers deploying web shells and reverse shells, escalating privileges, installing tools for persistent remote access, and running malicious code directly in memory. In some cases, attackers temporarily changed permissions on public directories to plant web shells, then restored the original settings to avoid detection.

The intruders also explored the wider Zimbra environments, identifying other mail servers and looking for trusted connections, such as existing SSH relationships, to move laterally between systems. On at least one compromised machine, attackers achieved root access and set up persistent command execution without requiring a password.

Mailbox data was a clear target. Attackers hunted for Zimbra credentials and authentication secrets. Microsoft uncovered a malicious tool built to extract service account credentials and pull mailbox information from Zimbra's databases. In another incident, attackers bundled recent mailbox backups into an archive and attempted to exfiltrate them to Azure Blob Storage using Microsoft's AzCopy utility. Microsoft could not confirm from the available evidence whether the transfer was successful.

Microsoft observed affected organizations across multiple regions and industries, with attacks ranging from automated exploitation to more deliberate hands-on-keyboard activity. The company has not attributed the activity to any specific threat actor.

Zimbra administrators still running versions earlier than 10.1.20 are urged to update immediately. Those unable to patch can reduce exposure by removing the optional SNMP package or disabling SNMP notifications. The early exploitation of this bug highlights the risk of vulnerabilities being discovered and exploited before public disclosure, even after a vendor has issued a fix.

§

Analysis

Why This Matters

  • Attackers exploited a critical vulnerability before public disclosure, meaning organizations that had not yet applied the patch were exposed to a 'zero-day' style threat.
  • The theft of credentials and mailbox data could lead to further compromise, identity theft, and business email compromise attacks.
  • The use of Microsoft's own AzCopy tool for exfiltration shows attackers using legitimate tools to blend in and avoid detection.

Background

Zimbra Collaboration Suite is a widely used open-core email and collaboration platform deployed by many organizations, including enterprises and government agencies. The vulnerability, CVE-2026-73570, exists in the optional SNMP monitoring feature when notifications are enabled. This feature is not installed by default, which may limit the attack surface but still leaves a significant number of servers exposed. The timeline of events indicates that the flaw was known to some parties before its public disclosure, raising questions about how the attackers obtained the details.

Key Perspectives

Microsoft Threat Intelligence: As the detector and reporter of this campaign, Microsoft highlights the sophistication of the attackers and the value they placed on mailbox data. Their analysis provides technical details to help defenders identify and remediate compromises. Zimbra (Synacor): Zimbra released a patch on July 20, before any known active exploitation, and disclosed the vulnerability publicly on August 13. The company continues to recommend that users apply the latest updates. Enterprise IT administrators: Those running Zimbra must prioritize patching and, if patching is not immediately possible, disable the vulnerable SNMP module to reduce risk. The incident underscores the need for rapid patch deployment and intrusion detection.

What to Watch

  • Whether additional threat actors begin exploiting CVE-2026-73570 now that it is publicly disclosed, leading to a broader wave of attacks.
  • Microsoft may publish further indicators of compromise (IOCs) to help organizations check for signs of prior exploitation.
  • The security community will watch for attribution efforts; if the attackers are linked to a known group, it could provide context about their broader objectives.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.