# Zimbra Users Urged to Update Amid Exploitation of Critical Vulnerability

*Published October 2, 2026*
*Source: [https://www.securityweek.com/zimbra-vulnerability-exploited-in-the-wild-prior-to-public-disclosure/](https://www.securityweek.com/zimbra-vulnerability-exploited-in-the-wild-prior-to-public-disclosure/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/zimbra-users-urged-to-update-amid-exploitation-of-critical-vulnerability) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A significant security flaw in the Zimbra Collaboration Suite has been actively exploited by hackers before it was publicly disclosed. Microsoft identified the vulnerability, tracked as CVE-2026-73570 with a CVSS score of 8.9, which stems from improperly sanitized input during SNMP notification processing in ZCS versions before 10.1.20. If the zimbra-snmp package is installed and notifications are enabled, attackers can exploit this flaw through crafted SMTP requests, allowing them to execute remote code with Zimbra user privileges.

Security patches addressing this issue were released on July 20 with ZCS version 10.1.20, and the vulnerability was publicly disclosed on August 13. Despite the patches, exploitation occurred between the patch release and public disclosure. Microsoft's observations revealed two distinct scanning tools probing the vulnerable injection point, indicating reconnaissance activity aimed at validating command execution without delivering a payload.

Following this initial probing, attackers deployed JSP webshells in accessible application directories and used tools like wget and curl to execute content and establish reverse shells. They utilized Zimbra's centralized service for credential exfiltration and leveraged existing SSH identities for further infiltration. The attackers also employed HTTP and HTTPS callbacks for command execution validation and deployed a remote-access agent for interactive shell access.

Zimbra users are strongly advised to update to version 10.1.20 or later, remove the optional SNMP package, disable the vulnerable configuration, and restrict SNMP and SMTP access. Conducting thorough checks for potential compromises is also recommended to ensure system security.
