CISA listed CVE-2026-73570 on the Known Exploited Vulnerabilities catalog on 2026-08-21, with a 2026-08-24 due date that already passed. The vulnerability is an unauthenticated OS command injection in Synacor's Zimbra Collaboration Suite (ZCS) SNMP notification path: when the optional zimbra-snmp package is installed and SNMP notifications are enabled, crafted SMTP traffic can yield OS command execution as the zimbra user. NVD rates it CVSS 3.1 8.9 HIGH (CWE-78).
This advisory reframes an overdue patching and forensic-triage obligation against a newer Microsoft Threat Intelligence narrative published 2026-09-30. Microsoft reports pre-disclosure probing of the vulnerable path between 2026-07-28 and 2026-08-07—after the permanent fix shipped, before public CVE disclosure—and documents post-exploitation activity observed after initial access. The CVE itself grants only zimbra-user execution under the SNMP precondition; root escalation, webshells, mailbox or credential theft, and lateral movement are Microsoft-observed post-exploitation, not attributes of the CVE.
Not every Zimbra install is vulnerable. Exposure requires the optional zimbra-snmp package and SNMP notifications enabled. Organizations still running ZCS before 10.1.20, especially internet-facing MTAs that meet that precondition, should treat residual patch debt and any pre-patch exposure window as priority review—not as a new zero-day discovery.
This issue is distinct from the older Zimbra KEV CVE-2025-27915 (Classic Web Client stored XSS, remediated in earlier 9.x/10.x patch trains). Different CWE class, vector, and fix release—do not conflate remediations.
Technical Information
CVE-2026-73570 is OS command injection (CWE-78) in the Zimbra Collaboration Suite SNMP monitoring / notification component. Per NVD, Microsoft, and Zimbra's Security Advisories wiki:
- An unauthenticated attacker can send crafted SMTP to a vulnerable ZCS instance.
- The injection path is reachable only when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
- Successful exploitation yields OS command execution as the zimbra service account—not root.
- NVD CVSS 3.1 base score 8.9 HIGH — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L (source cve@mitre.org, Secondary; NVD status Analyzed as of lastModified 2026-08-24).
- Attack surface emphasis from Microsoft: internet-facing Zimbra mail / MTA paths receiving crafted SMTP.
CVE vs post-exploitation (keep the split sharp):
| Layer | What | Attribution |
|---|---|---|
| CVE itself | Unauth SMTP → command injection as zimbra user when zimbra-snmp + SNMP notifications enabled | NVD / Zimbra / Microsoft vulnerability description |
| Post-exploitation (Microsoft-observed) | JSP webshells in Jetty/mailboxd paths; reverse shells; LPE to root via Zimbra helpers/PAM; credential and auth-key collection; mailbox DB/backup staging; lateral movement via zimbra SSH identity; optional RATs/miners | Microsoft TI 2026-09-30 — not the CVE definition |
Timeline (sourced):
| Date | Event |
|---|---|
| 2026-06-26 | Zimbra security advisory with temporary mitigation for the SNMP command-injection issue (pre-permanent patch) |
| 2026-07-20 | ZCS 10.1.20 released — permanent fix |
| 2026-07-28 – 2026-08-07 | Microsoft observes two distinct out-of-band scanning tools probing the vulnerable injection path (pre-disclosure) |
| 2026-08-13 | CVE-2026-73570 publicly disclosed / NVD published |
| 2026-08-17 | CERT Polska flagged as exploited / IoCs (per SecurityWeek secondary citing CERT.PL) |
| 2026-08-21 | CISA adds CVE-2026-73570 to KEV (dateAdded) |
| 2026-08-24 | CISA KEV dueDate (forensic triage Yes; BOD 26-04) — overdue as of this advisory |
| 2026-09-30 | Microsoft Threat Intelligence blog: exploitation narrative, ATT&CK map, IoCs |
| 2026-10-01 | SecurityWeek and The Register coverage of the Microsoft narrative |
MITRE ATT&CK (Microsoft-attributed only): CVE-aligned initial access is approximately T1190 (Exploit Public-Facing Application)—crafted SMTP against the SNMP notification path as the zimbra account. Microsoft's published table also maps reconnaissance (T1595.002 Active Scanning: Vulnerability Scanning for pre-exploit OOB probes) and a range of post-exploitation techniques including Unix Shell (T1059.004), Ingress Tool Transfer (T1105), Exploitation for Privilege Escalation (T1068), Cron (T1053.003), Systemd Service (T1543.002), Web Shell (T1505.003), Masquerading (T1036.005), Reflective Code Loading (T1620), File and Directory Discovery (T1083), Web Protocols (T1071.001), Dead Drop Resolver (T1102.001), Archive via Utility (T1560.001), Local Data Staging (T1074.001), and Resource Hijacking (T1496, campaign-observed miner). Rows other than T1190 (and immediate shell execution) are post-exploitation, not CVE primitives.
CISA KEV knownRansomwareCampaignUse is Unknown. Microsoft describes targeting across "more than one region and industry" without naming victims; this advisory invents none.
Affected Product Versions
| Item | Detail |
|---|---|
| Vendor / product | Synacor / Zimbra Collaboration Suite (ZCS); NVD CPE cpe:2.3:a:synacor:zimbra_collaboration_suite; KEV vendorProject Synacor |
| Affected versions | ZCS before 10.1.20 (NVD: versionEndExcluding 10.1.20) |
| Precondition (hard) | Optional zimbra-snmp package installed AND SNMP notifications enabled — not all Zimbra installs are vulnerable |
| Fixed version | ZCS 10.1.20 (2026-07-20) and later |
| Privilege of CVE execution | zimbra user / Zimbra service account |
| Attack surface | Internet-facing Zimbra mail / MTA path receiving crafted SMTP |
Installations without zimbra-snmp, or with SNMP notifications disabled, fall outside the NVD/Microsoft/Zimbra vulnerability description for this CVE. Inventory must check package presence and notification configuration—not version alone.
Workaround and Mitigation
- Temporary mitigation (vendor advisory 2026-06-26): Zimbra published a security advisory with temporary mitigation for the SNMP command-injection issue before the permanent patch. Exact step text of that June advisory was not separately extracted in the source pack used for this draft; treat the Microsoft-listed compensating controls below as the practical interim options when upgrade is delayed.
- Permanent fix: Upgrade to ZCS 10.1.20 or later (released 2026-07-20). Zimbra's Patch Release Update blog and Security Advisories wiki both identify 10.1.20 as the fix release for the SNMP command-injection issue when SNMP notifications are enabled.
- If patching is delayed (Microsoft TI mitigations): (1) uninstall the optional zimbra-snmp package; (2) disable SNMP notifications; (3) restrict SNMP and SMTP access to trusted hosts only.
- KEV / forensic angle: CISA required action references vendor mitigations, compliance with BOD 26-04, and forensic triage (forensicTriage: Yes). The 2026-08-24 due date has passed—federal stakeholders remain under that obligation; commercial operators should apply analogous urgency for any pre-10.1.20 exposure window, especially hosts that had zimbra-snmp + SNMP notifications and internet-facing SMTP.
Indicators of Compromise
All indicators below are Microsoft-published campaign IoCs from the 2026-09-30 Threat Intelligence blog. They are attributed to observed exploitation and post-exploitation activity—not CVE primitives. No Zimbra- or CISA-published IoC list was separately extracted for this pack beyond KEV notes and a secondary CERT.PL pointer.
Network indicators (Microsoft)
| Indicator | Role (as Microsoft) |
|---|---|
| 117.107.25[.]243:7071 | Dropper C2 |
| 192.255.193[.]111:9004 | Miner C2 |
| transzimbra[.]linkpc[.]net | Dynamic-DNS dropper |
| psk1zim[.]abrdns[.]com/agentws ; tls[.]psk1zim[.]abrdns[.]com | zimclient2 C2 |
| wslogzimbra[.]linkpc[.]net/wsstat | Installer status |
| mexico-cashpay-test.s3.dualstack.mx-central-1.amazonaws[.]com/pakistan/2026/aliyun_update.tar.gz | S3 dropper |
| 45.32.30[.]235:8081 / :8080 | Reverse shell |
| 193.42.40[.]135:443 ; 3.209.137[.]175:443 | C2 |
| oast[.]fun, oast[.]online, dnslog[.]pp[.]ua, requestrepo[.]com, bypass[.]eu[.]org | OOB probe infrastructure cited by MS |
| User-Agent ZB73570 | Probe User-Agent string cited by MS |
File hashes SHA-256 (Microsoft)
| SHA-256 | Label (as Microsoft) |
|---|---|
| dee5af1c0f76b45d28bafd6e60c07bb8e391d98addf81ef8f13d073acdb3c48a | de.sh |
| aea991f694911e321b0ab97534f2ad0291c392c0a43dabff664c563618bd036d | build_amd64 |
| 6ab7de2509038edf580aef6229c1c3db17f4da8f2d7d940818faf617d1938244 | agent2.sh |
| bf28f38122bf20d5fac969cc414daa6a890cdea872d389ca93d2092b6b7773cf | zimdown2 |
| b594a42b8f1c6f090327bb9a3361c2d3515537fb7ac8da6b9061b9a3f330e159 | Zimclient2 |
| 65A7576C389326B6CDF9C993D0BE6E5D50FED9655D1CDF2A3A50F2C21C8EC435 | Looptik LPE toolkit |
| 22EF852F6EBC39EE71235B90648B4B200B385C47D25C79545986493F8C70DB69 | Loader (systemd-resolved masquerade) |
| 518FE65DD349180191D9B258AB24876AAED6613CD657D0B626D1FC24E03A22B6 | In-memory stage 2 |
Hunting should also consider Microsoft-described post-exploit artifacts (webshells under Jetty/mailboxd paths, unexpected systemd units such as zimlog.service-style persistence, abuse of zimbra SSH identity, and secret rotation candidates for PreAuth/AuthToken keys)—again as Microsoft-observed post-exploitation, not as CVE requirements.
Why this matters for third-party risk
Self-hosted and MSP-operated Zimbra Collaboration is a mail and collaboration control plane: authentication secrets, mailbox stores, and MTA trust sit there, so a zimbra-user foothold with subsequent post-exploitation has high blast radius for email confidentiality and cluster lateral movement. TPRM owners should inventory ZCS versions, presence of zimbra-snmp, whether SNMP notifications are enabled, and internet exposure of SMTP/MTA; demand 10.1.20+ (or compensating removal/disable/restriction of SNMP/SMTP); prioritize internet-facing MTAs; and require forensic review for any pre-patch exposure window—aligned with KEV forensic triage language—before accepting residual risk.
Book a demo: https://www.rescana.com/#contact
If you own vendor risk for a self-hosted or MSP Zimbra mail stack, forward this advisory to the TPRM owner responsible for mail/collaboration platforms and ask them to confirm version, zimbra-snmp status, and forensic coverage for any host that was internet-facing before 10.1.20.



