Full Report
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog.
Analysis Summary
# Vulnerability: Unauthenticated OS Command Injection in Zimbra SNMP Notifications
## CVE Details
- **CVE ID:** CVE-2026-73570
- **CVSS Score:** Not explicitly listed in text, but categorized as critical due to unauthenticated remote command execution (RCE).
- **CWE:** CWE-78 (Improper Neutralization of Special Elements used in an OS Command / OS Command Injection)
## Affected Systems
- **Products:** Zimbra Collaboration Suite
- **Versions:** Versions prior to 10.1.20.
- **Configurations:** The vulnerability is exploitable only if:
1. The optional `zimbra-snmp` package is installed.
2. SNMP notifications are enabled.
3. The server is internet-facing (receives external SMTP requests).
## Vulnerability Description
CVE-2026-73570 is an OS command injection flaw located within the SNMP notification path of the Zimbra Collaboration Suite. The vulnerability occurs because the system fails to sufficiently sanitize untrusted input introduced via specially crafted SMTP requests. When a service-state change triggers an SNMP trap, the malicious input is passed to the `swatchdog-to-snmptrap` execution path, allowing embedded shell commands to execute with the privileges of the `zimbra` service account.
## Exploitation
- **Status:** Exploited in the wild. Microsoft observed pre-disclosure reconnaissance starting July 28, 2026, followed by active exploitation involving JSP web shells and data exfiltration.
- **Complexity:** Low (requires no authentication or user interaction).
- **Attack Vector:** Network (Remote via SMTP).
## Impact
- **Confidentiality:** High (Attacker access to email, authentication data, and mailbox archives).
- **Integrity:** High (Ability to deploy web shells, modify files, and escalate privileges).
- **Availability:** High (Potential for full system takeover and persistent remote access).
## Remediation
### Patches
- **Zimbra 10.1.20:** Released July 20, 2026. Users should upgrade to this version or later immediately.
### Workarounds
- Disable SNMP notifications if not strictly required.
- Uninstall the optional `zimbra-snmp` package.
- Implement strict ingress filtering on SMTP traffic to block common shell metacharacters, though this is not a substitute for patching.
## Detection
- **Indicators of Compromise (IoCs):**
- Out-of-band callbacks to subdomains: `oast[.]fun`, `oast[.]online`, `dnslog[.]pp[.]ua`, `requestrepo[.]com`, and `bypass[.]eu[.]org`.
- Specific User-Agent: `ZB73570`.
- Commands observed in logs: `curl`, `wget`, `ping`, `nslookup`, and `id` targeting external domains.
- Presence of unauthorized JSP web shells in the Zimbra webroot.
- **Detection Methods:**
- Monitor for unusual child processes spawning from `swatchdog` or `snmptrap`.
- Audit network logs for unauthorized outbound connections from mail servers to public interaction/collaborator services.
## References
- **Vendor Advisory:** Zimbra Security Release (July 20, 2026)
- **Microsoft Security Blog:** [https://www.microsoft[.]com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/]
- **MITRE ATT&CK:** Mapped to T1059 (Command and Scripting Interpreter) and T1190 (Exploit Public-Facing Application).