Zimbra Collaboration CVE-2026-73570 — Unauthenticated OS Command Injection via Crafted SMTP (KEV)

Zimbra Collaboration CVE-2026-73570 — Unauthenticated OS Command Injection via Crafted SMTP (KEV)

CISA listed CVE-2026-73570 on the Known Exploited Vulnerabilities catalog on 2026-08-21, with a 2026-08-24 due date that already passed. The vulnerability is an unauthenticated OS command injection in Synacor's Zimbra Collaboration Suite (ZCS) SNMP notification path: when the optional zimbra-snmp package is installed and SNMP notifications are enabled, crafted SMTP traffic can yield OS command execution as the zimbra user. NVD rates it CVSS 3.1 8.9 HIGH (CWE-78).

This advisory reframes an overdue patching and forensic-triage obligation against a newer Microsoft Threat Intelligence narrative published 2026-09-30. Microsoft reports pre-disclosure probing of the vulnerable path between 2026-07-28 and 2026-08-07—after the permanent fix shipped, before public CVE disclosure—and documents post-exploitation activity observed after initial access. The CVE itself grants only zimbra-user execution under the SNMP precondition; root escalation, webshells, mailbox or credential theft, and lateral movement are Microsoft-observed post-exploitation, not attributes of the CVE.

Not every Zimbra install is vulnerable. Exposure requires the optional zimbra-snmp package and SNMP notifications enabled. Organizations still running ZCS before 10.1.20, especially internet-facing MTAs that meet that precondition, should treat residual patch debt and any pre-patch exposure window as priority review—not as a new zero-day discovery.

This issue is distinct from the older Zimbra KEV CVE-2025-27915 (Classic Web Client stored XSS, remediated in earlier 9.x/10.x patch trains). Different CWE class, vector, and fix release—do not conflate remediations.

Technical Information

CVE-2026-73570 is OS command injection (CWE-78) in the Zimbra Collaboration Suite SNMP monitoring / notification component. Per NVD, Microsoft, and Zimbra's Security Advisories wiki:

  • An unauthenticated attacker can send crafted SMTP to a vulnerable ZCS instance.
  • The injection path is reachable only when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
  • Successful exploitation yields OS command execution as the zimbra service account—not root.
  • NVD CVSS 3.1 base score 8.9 HIGH — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L (source cve@mitre.org, Secondary; NVD status Analyzed as of lastModified 2026-08-24).
  • Attack surface emphasis from Microsoft: internet-facing Zimbra mail / MTA paths receiving crafted SMTP.

CVE vs post-exploitation (keep the split sharp):

Layer What Attribution
CVE itself Unauth SMTP → command injection as zimbra user when zimbra-snmp + SNMP notifications enabled NVD / Zimbra / Microsoft vulnerability description
Post-exploitation (Microsoft-observed) JSP webshells in Jetty/mailboxd paths; reverse shells; LPE to root via Zimbra helpers/PAM; credential and auth-key collection; mailbox DB/backup staging; lateral movement via zimbra SSH identity; optional RATs/miners Microsoft TI 2026-09-30 — not the CVE definition

Timeline (sourced):

Date Event
2026-06-26 Zimbra security advisory with temporary mitigation for the SNMP command-injection issue (pre-permanent patch)
2026-07-20 ZCS 10.1.20 released — permanent fix
2026-07-28 – 2026-08-07 Microsoft observes two distinct out-of-band scanning tools probing the vulnerable injection path (pre-disclosure)
2026-08-13 CVE-2026-73570 publicly disclosed / NVD published
2026-08-17 CERT Polska flagged as exploited / IoCs (per SecurityWeek secondary citing CERT.PL)
2026-08-21 CISA adds CVE-2026-73570 to KEV (dateAdded)
2026-08-24 CISA KEV dueDate (forensic triage Yes; BOD 26-04) — overdue as of this advisory
2026-09-30 Microsoft Threat Intelligence blog: exploitation narrative, ATT&CK map, IoCs
2026-10-01 SecurityWeek and The Register coverage of the Microsoft narrative

MITRE ATT&CK (Microsoft-attributed only): CVE-aligned initial access is approximately T1190 (Exploit Public-Facing Application)—crafted SMTP against the SNMP notification path as the zimbra account. Microsoft's published table also maps reconnaissance (T1595.002 Active Scanning: Vulnerability Scanning for pre-exploit OOB probes) and a range of post-exploitation techniques including Unix Shell (T1059.004), Ingress Tool Transfer (T1105), Exploitation for Privilege Escalation (T1068), Cron (T1053.003), Systemd Service (T1543.002), Web Shell (T1505.003), Masquerading (T1036.005), Reflective Code Loading (T1620), File and Directory Discovery (T1083), Web Protocols (T1071.001), Dead Drop Resolver (T1102.001), Archive via Utility (T1560.001), Local Data Staging (T1074.001), and Resource Hijacking (T1496, campaign-observed miner). Rows other than T1190 (and immediate shell execution) are post-exploitation, not CVE primitives.

CISA KEV knownRansomwareCampaignUse is Unknown. Microsoft describes targeting across "more than one region and industry" without naming victims; this advisory invents none.

Affected Product Versions

Item Detail
Vendor / product Synacor / Zimbra Collaboration Suite (ZCS); NVD CPE cpe:2.3:a:synacor:zimbra_collaboration_suite; KEV vendorProject Synacor
Affected versions ZCS before 10.1.20 (NVD: versionEndExcluding 10.1.20)
Precondition (hard) Optional zimbra-snmp package installed AND SNMP notifications enabled — not all Zimbra installs are vulnerable
Fixed version ZCS 10.1.20 (2026-07-20) and later
Privilege of CVE execution zimbra user / Zimbra service account
Attack surface Internet-facing Zimbra mail / MTA path receiving crafted SMTP

Installations without zimbra-snmp, or with SNMP notifications disabled, fall outside the NVD/Microsoft/Zimbra vulnerability description for this CVE. Inventory must check package presence and notification configuration—not version alone.

Workaround and Mitigation

  1. Temporary mitigation (vendor advisory 2026-06-26): Zimbra published a security advisory with temporary mitigation for the SNMP command-injection issue before the permanent patch. Exact step text of that June advisory was not separately extracted in the source pack used for this draft; treat the Microsoft-listed compensating controls below as the practical interim options when upgrade is delayed.
  2. Permanent fix: Upgrade to ZCS 10.1.20 or later (released 2026-07-20). Zimbra's Patch Release Update blog and Security Advisories wiki both identify 10.1.20 as the fix release for the SNMP command-injection issue when SNMP notifications are enabled.
  3. If patching is delayed (Microsoft TI mitigations): (1) uninstall the optional zimbra-snmp package; (2) disable SNMP notifications; (3) restrict SNMP and SMTP access to trusted hosts only.
  4. KEV / forensic angle: CISA required action references vendor mitigations, compliance with BOD 26-04, and forensic triage (forensicTriage: Yes). The 2026-08-24 due date has passed—federal stakeholders remain under that obligation; commercial operators should apply analogous urgency for any pre-10.1.20 exposure window, especially hosts that had zimbra-snmp + SNMP notifications and internet-facing SMTP.

Indicators of Compromise

All indicators below are Microsoft-published campaign IoCs from the 2026-09-30 Threat Intelligence blog. They are attributed to observed exploitation and post-exploitation activity—not CVE primitives. No Zimbra- or CISA-published IoC list was separately extracted for this pack beyond KEV notes and a secondary CERT.PL pointer.

Network indicators (Microsoft)

Indicator Role (as Microsoft)
117.107.25[.]243:7071 Dropper C2
192.255.193[.]111:9004 Miner C2
transzimbra[.]linkpc[.]net Dynamic-DNS dropper
psk1zim[.]abrdns[.]com/agentws ; tls[.]psk1zim[.]abrdns[.]com zimclient2 C2
wslogzimbra[.]linkpc[.]net/wsstat Installer status
mexico-cashpay-test.s3.dualstack.mx-central-1.amazonaws[.]com/pakistan/2026/aliyun_update.tar.gz S3 dropper
45.32.30[.]235:8081 / :8080 Reverse shell
193.42.40[.]135:443 ; 3.209.137[.]175:443 C2
oast[.]fun, oast[.]online, dnslog[.]pp[.]ua, requestrepo[.]com, bypass[.]eu[.]org OOB probe infrastructure cited by MS
User-Agent ZB73570 Probe User-Agent string cited by MS

File hashes SHA-256 (Microsoft)

SHA-256 Label (as Microsoft)
dee5af1c0f76b45d28bafd6e60c07bb8e391d98addf81ef8f13d073acdb3c48a de.sh
aea991f694911e321b0ab97534f2ad0291c392c0a43dabff664c563618bd036d build_amd64
6ab7de2509038edf580aef6229c1c3db17f4da8f2d7d940818faf617d1938244 agent2.sh
bf28f38122bf20d5fac969cc414daa6a890cdea872d389ca93d2092b6b7773cf zimdown2
b594a42b8f1c6f090327bb9a3361c2d3515537fb7ac8da6b9061b9a3f330e159 Zimclient2
65A7576C389326B6CDF9C993D0BE6E5D50FED9655D1CDF2A3A50F2C21C8EC435 Looptik LPE toolkit
22EF852F6EBC39EE71235B90648B4B200B385C47D25C79545986493F8C70DB69 Loader (systemd-resolved masquerade)
518FE65DD349180191D9B258AB24876AAED6613CD657D0B626D1FC24E03A22B6 In-memory stage 2

Hunting should also consider Microsoft-described post-exploit artifacts (webshells under Jetty/mailboxd paths, unexpected systemd units such as zimlog.service-style persistence, abuse of zimbra SSH identity, and secret rotation candidates for PreAuth/AuthToken keys)—again as Microsoft-observed post-exploitation, not as CVE requirements.

Why this matters for third-party risk

Self-hosted and MSP-operated Zimbra Collaboration is a mail and collaboration control plane: authentication secrets, mailbox stores, and MTA trust sit there, so a zimbra-user foothold with subsequent post-exploitation has high blast radius for email confidentiality and cluster lateral movement. TPRM owners should inventory ZCS versions, presence of zimbra-snmp, whether SNMP notifications are enabled, and internet exposure of SMTP/MTA; demand 10.1.20+ (or compensating removal/disable/restriction of SNMP/SMTP); prioritize internet-facing MTAs; and require forensic review for any pre-patch exposure window—aligned with KEV forensic triage language—before accepting residual risk.

Book a demo: https://www.rescana.com/#contact

If you own vendor risk for a self-hosted or MSP Zimbra mail stack, forward this advisory to the TPRM owner responsible for mail/collaboration platforms and ask them to confirm version, zimbra-snmp status, and forensic coverage for any host that was internet-facing before 10.1.20.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.