Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Eight-step diagram of a Zimbra SNMP command-injection attack chain from initial access through exfiltration.
Photo/figure: Microsoft Security Research / Microsoft Security Blog, Sep 30, 2026. Figure 1. CVE-2026-73570 attack chain (fair use).

Response

Microsoft Tracks Unauthenticated Zimbra SNMP Command Injection Exploited as CVE-2026-73570

Microsoft Security Research published findings on September 30, 2026, tracking unauthenticated OS command injection in the Zimbra Collaboration Suite SNMP notification path as CVE-2026-73570, with post-exploitation webshells, privilege escalation, credential theft, and mailbox staging observed on internet-facing mail servers.

Noah Park, ResponseNew York7 min read

NEW YORK - Microsoft Security Research published findings on September 30, 2026, tracking exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Researchers Mahesh Mandava and Rajesh Kumar Natarajan reported that a specially crafted SMTP or email request can trigger the flaw on internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled, without authentication or user interaction. Commands run with the privileges of the zimbra service account.

Shell snippet that writes a JSP webshell into the Zimbra public webroot.
Photo/figure: Microsoft Security Research, Figure 3. Command-injection sequence that changes webroot permissions, reconstructs encoded fragments, and deploys a JSP webshell.The injection sequence Microsoft described, ending in a JSP webshell.

Zimbra Collaboration Suite 10.1.20, released July 20, 2026, contains the remediation. The CVE was publicly disclosed on August 13, 2026. Microsoft telemetry identified probing of the same injection path between July 28 and August 7, after the fix shipped and before public disclosure. Operators used lightweight out-of-band callbacks to collaborator services to confirm command execution before delivering payloads.

After successful exploitation, Microsoft observed JSP webshells written into Zimbra application and servlet-work directories, reverse shells, and privilege escalation that abused writable zmmailboxdmgr log paths together with PAM and sudo helpers to obtain passwordless root for the zimbra account. Persistence included a disguised zimlog.service systemd unit installed outside Zimbra application directories and timestomped to resemble legitimate services. Actors harvested service credentials with zmlocalconfig and authenticated LDAP queries for high-value attributes including zimbraPreAuthKey and zimbraAuthTokenKey, moved laterally with the existing zimbra SSH identity and rsync, deployed the zimclient2 remote-access agent via multi-stage downloaders, and on at least one host staged mailbox-backup content as /opt/zimbra/final.tar.gz before attempting Azure Blob transfer with AzCopy. Microsoft did not confirm that that transfer completed successfully.

File list of a zimbra-exfil client that dumps local configuration and secrets.
Photo/figure: Microsoft Security Research, Figure 12. zimbra-exfil client-dump binary workflow for reading localconfig.xml and extracting service-account credentials.Functions that dump local configuration, LDAP, and secrets.
Disassembly listing mailbox, metadata, and session export strings.
Photo/figure: Microsoft Security Research, Figure 13. Automated export of Zimbra mailbox, metadata, mobile-device, out-of-office, and related database content.Mailbox, metadata, devices, and session tables named in the export routine.
Table of staged Zimbra credential, certificate, and mail-rule output files.
Photo/figure: Microsoft Security Research, Figure 14. Credential, certificate, LDAP secret, mail-rule, and configuration artifacts collected and staged by the Zimbra exfiltration-attempt implant.Certificates, auth keys, DKIM, sieve rules, and password material staged for collection.

For SOC and incident response teams, Microsoft published Defender coverage including Exploit:Linux/SnmpTrapCmdInject.A and additional detections across webshell drop, privilege escalation, credential access, and reverse-shell behaviors, plus Advanced Hunting KQL in the blog for SNMP injection lineage, suspicious JSP writes, Java-launched shells, memfd-backed execution, zimlog.service and PAM artifacts, DNS callbacks, and archive or AzCopy staging. Immediate response work is inventory of internet-facing Zimbra hosts still below 10.1.20, confirmation whether zimbra-snmp and SNMP notifications remain enabled, patching to 10.1.20 or later, or uninstalling zimbra-snmp and disabling SNMP notifications until patching is possible. Rotate domain zimbraPreAuthKey values, hunt unexpected JSP files across mailbox nodes, and review systemd units for unexpected ownership, enablement, or timestamp changes.

Sources:


Noah Park covers incident response, containment, and blue-team operations for SOCtember from New York.

Related stories

Response desk