CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 9010

As cited

Copy frozen at (site build).

vulnerabilities

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft Threat Intelligence documented active exploitation of CVE-2026-73570, an unauthenticated command-injection flaw in Zimbra Collaboration Suite affecting internet-facing mail servers with the optional SNMP package installed. Attackers deployed web shells, reverse shells, and credential-stealing implants to extract authentication material, mailbox data, and service secrets from compromised environments across multiple sectors and regions. The attack chain included privilege escalation via PAM manipulation, lateral movement through SSH trust relationships, and attempted exfiltration using cloud storage tools.

Why it matters: Organizations running Zimbra versions before 10.1.20 with SNMP notifications enabled face immediate remote code execution risk without authentication; apply patch urgently and rotate authentication keys, SSH identities, and Zimbra service secrets on all mail servers.

VendorsMicrosoftAmazon Web ServicesOracleGitHubOpenSSL
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft Threat Intelligence documented active exploitation of CVE-2026-73570, an unauthenticated command-injection flaw in Zimbra Collaboration Suite affecting internet-facing mail servers with the optional SNMP package installed. Attackers deployed web shells, reverse shells, and credential-stealing implants to extract authentication material, mailbox data, and service secrets from compromised environments across multiple sectors and regions. The attack chain included privilege escalation via PAM manipulation, lateral movement through SSH trust relationships, and attempted exfiltration using cloud storage tools.

Why it matters: Organizations running Zimbra versions before 10.1.20 with SNMP notifications enabled face immediate remote code execution risk without authentication; apply patch urgently and rotate authentication keys, SSH identities, and Zimbra service secrets on all mail servers.

VendorsAmazon Web ServicesGitHubMicrosoftOpenSSLOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft Threat Intelligence documented active exploitation of CVE-2026-73570, an unauthenticated command-injection flaw in Zimbra Collaboration Suite affecting internet-facing mail servers with the optional SNMP package installed. Attackers deployed web shells, reverse shells, and credential-stealing implants to extract authentication material, mailbox data, and service secrets from compromised environments across multiple sectors and regions. The attack chain included privilege escalation via PAM manipulation, lateral movement through SSH trust relationships, and attempted exfiltration using cloud storage tools.

Why it matters: Organizations running Zimbra versions before 10.1.20 with SNMP notifications enabled face immediate remote code execution risk without authentication; apply patch urgently and rotate authentication keys, SSH identities, and Zimbra service secrets on all mail servers.

VendorsAmazon Web ServicesGitHubMicrosoftOpenSSLOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft Threat Intelligence documented active exploitation of CVE-2026-73570, an unauthenticated command-injection flaw in Zimbra Collaboration Suite affecting internet-facing mail servers with the optional SNMP package installed. Attackers deployed web shells, reverse shells, and credential-stealing implants to extract authentication material, mailbox data, and service secrets from compromised environments across multiple sectors and regions. The attack chain included privilege escalation via PAM manipulation, lateral movement through SSH trust relationships, and attempted exfiltration using cloud storage tools.

Why it matters: Organizations running Zimbra versions before 10.1.20 with SNMP notifications enabled face immediate remote code execution risk without authentication; apply patch urgently and rotate authentication keys, SSH identities, and Zimbra service secrets on all mail servers.

VendorsAmazon Web ServicesGitHubMicrosoftOpenSSLOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary