Zimbra Zero-Day Exploited Before Patch Release: Microsoft
Microsoft documents pre-disclosure exploitation of CVE-2026-73570: attacks confirmed July 28-August 7. Webshell deployment and systemd persistence observed.

Exploitation of CVE-2026-73570 started before Synacor disclosed the vulnerability publicly. Confirmed. Microsoft documented the activity in a September 30 security blog post, reported by SecurityWeek on October 1.
Timeline
The patch shipped with Zimbra ZCS 10.1.20 on July 20, 2026. Public disclosure: August 13. Microsoft observed two distinct out-of-band scanning tools probing the vulnerable SNMP handler between July 28 and August 7: eleven days after a patch existed, twenty-four days before a public advisory existed.
Defenders who depend on public CVE announcements as their patch trigger were exposed during that entire window. Organizations that patched on the July 20 release were not.
Vulnerability recap
CVE-2026-73570 is an OS command injection in Zimbra Collaboration Suite’s SNMP notification processing. CVSS 8.9 (high). Under certain mail-delivery conditions the flaw is reachable via specially crafted emails without user interaction. No click required from the mailbox owner.
Affected versions: ZCS before 10.1.20. Patch: 10.1.20, July 20, 2026. CISA added CVE-2026-73570 to the Known Exploited Vulnerabilities catalog in August 2026.
Post-exploitation activity (confirmed, per Microsoft)
Once command execution was validated, attackers followed the same sequence:
- JSP webshells written to accessible application directories on the ZCS host
- Root access obtained via legitimate Zimbra-bundled administrative tools, not external privilege-escalation exploits
- Persistence via a systemd service named
_zimlog.service_, surviving reboots - Credential exfiltration and LDAP secret access
_zimlog.service_ is a confirmed compromise indicator for organizations inside the July 28-August 7 window. Absence does not confirm clean access.
CERT Polska
Poland’s CERT Polska flagged active exploitation on August 17 with published indicators of compromise, ahead of the Microsoft analysis that established the pre-disclosure timeline.
Status
Patch is available. CVE-2026-73570 is KEV-listed. Active exploitation ran for weeks before a public advisory named it. For organizations inside the July 28-August 7 window: CVE-2026-73570 was active before a public advisory existed to prompt response. Patch status and compromise assessment are separate questions.
Prior coverage
- 270 Zimbra servers breached as the KEV deadline expired
- Zimbra SNMP RCE Now Exploited in the Wild
- Zimbra 10.1.20 patches nine bugs, SNMP injection at the top
Full CVE details: CVE-2026-73570.
- [ HIGH ]CVE-2026-73570Zimbra ZCS SNMP Command Injection — Unauthenticated RCE
Found this useful? Share it.


