Skip to content
feed: live
>_0dayNews
zimbra
● Breaking

Zimbra Zero-Day Exploited Before Patch Release: Microsoft

Microsoft documents pre-disclosure exploitation of CVE-2026-73570: attacks confirmed July 28-August 7. Webshell deployment and systemd persistence observed.

Zimbra Zero-Day Exploited Before Patch Release: Microsoft
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Exploitation of CVE-2026-73570 started before Synacor disclosed the vulnerability publicly. Confirmed. Microsoft documented the activity in a September 30 security blog post, reported by SecurityWeek on October 1.

Timeline

The patch shipped with Zimbra ZCS 10.1.20 on July 20, 2026. Public disclosure: August 13. Microsoft observed two distinct out-of-band scanning tools probing the vulnerable SNMP handler between July 28 and August 7: eleven days after a patch existed, twenty-four days before a public advisory existed.

Defenders who depend on public CVE announcements as their patch trigger were exposed during that entire window. Organizations that patched on the July 20 release were not.

Vulnerability recap

CVE-2026-73570 is an OS command injection in Zimbra Collaboration Suite’s SNMP notification processing. CVSS 8.9 (high). Under certain mail-delivery conditions the flaw is reachable via specially crafted emails without user interaction. No click required from the mailbox owner.

Affected versions: ZCS before 10.1.20. Patch: 10.1.20, July 20, 2026. CISA added CVE-2026-73570 to the Known Exploited Vulnerabilities catalog in August 2026.

Post-exploitation activity (confirmed, per Microsoft)

Once command execution was validated, attackers followed the same sequence:

  • JSP webshells written to accessible application directories on the ZCS host
  • Root access obtained via legitimate Zimbra-bundled administrative tools, not external privilege-escalation exploits
  • Persistence via a systemd service named _zimlog.service_, surviving reboots
  • Credential exfiltration and LDAP secret access

_zimlog.service_ is a confirmed compromise indicator for organizations inside the July 28-August 7 window. Absence does not confirm clean access.

CERT Polska

Poland’s CERT Polska flagged active exploitation on August 17 with published indicators of compromise, ahead of the Microsoft analysis that established the pre-disclosure timeline.

Status

Patch is available. CVE-2026-73570 is KEV-listed. Active exploitation ran for weeks before a public advisory named it. For organizations inside the July 28-August 7 window: CVE-2026-73570 was active before a public advisory existed to prompt response. Patch status and compromise assessment are separate questions.

Prior coverage

Full CVE details: CVE-2026-73570.

Related CVEs
  • [ HIGH ]CVE-2026-73570Zimbra ZCS SNMP Command Injection — Unauthenticated RCE

Found this useful? Share it.