6 October 2026 8 min read

CVE-2026-73570: Zimbra Command Injection via SNMP Is Being Exploited—Update to 10.1.20 and Check for Compromise

A crafted email is all it takes: On Zimbra servers with the zimbra-snmp package and SNMP notifications enabled, attackers can execute commands as the zimbra user without authentication (CVE-2026-73570, CVSS 8.9). The vulnerability is being exploited and was fixed in 10.1.20. Update, apply the workaround until then, and check for web shells and persistence.

In Zimbra Collaboration (ZCS) prior to version 10.1.20, an unauthenticated attacker can execute operating system commands with the privileges of the zimbra user if the optional zimbra-snmp package is installed and SNMP notifications are enabled. The trigger is a crafted SMTP request—that is, an email to the server—whose contents reach SNMP notification processing without filtering. The vulnerability is identified as CVE-2026-73570 and has a CVSS score of 8.9. Zimbra reported it on June 26, 2026, and fixed it in version 10.1.20 on July 20, 2026. CERT Polska warned of an active attack campaign on August 17, 2026; the U.S. agency CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on August 21, 2026. The update is available.

Support with updating and checking

If you need help securing, checking for compromise, or updating Zimbra Collaboration, please use the contact form on adeptio.ch. I can also get back to you at short notice.

Key points at a glance

FeatureDetails
AdvisoryZimbra Security Advisory of June 26, 2026 (temporary mitigation), fix in ZCS 10.1.20 of July 20, 2026
CVECVE-2026-73570, published August 13, 2026
RatingCVSS 3.1: 8.9 (high), AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Vulnerability typeOS Command Injection (CWE-78) in SNMP notification processing (swatchdog)
Prerequisitesno authentication; zimbra-snmp package installed, SNMP notifications enabled through snmp_notify, swatchdog service running
Affected versionsZCS prior to 10.1.20
Fixed versionsZCS 10.1.20 and later
Exploitationconfirmed by CERT Polska (report of August 17, 2026); in CISA KEV since August 21, 2026
CISA deadline for U.S. federal agenciesAugust 24, 2026
WorkaroundDisable SNMP notifications or uninstall zimbra-snmp; restrict SNMP and SMTP to trusted hosts

Affected versions and updates

Version branchAffectedFixed
ZCS 10.110.1.x prior to 10.1.2010.1.20 and later
older branches (10.0, 9.0)yes, according to NVD all versions prior to 10.1.20no fixed version named in the Sources (as of October 6, 2026); move to 10.1.20 or later

Only installations with zimbra-snmp installed and SNMP notifications enabled are affected. According to CERT Polska, the swatchdog service that processes notifications runs by default. Without zimbra-snmp, a server cannot be attacked through this path according to the advisory description; the update to 10.1.20 also fixes additional vulnerabilities (XSS in the Classic Web Client, bypass of forwarding restrictions, SSRF in the Nextcloud integration, access controls in EWS and mailbox delegation), so it is advisable even without SNMP.

The installed version is displayed by zmcontrol -v as the zimbra user (release number, build, platform, and build date according to the Zimbra Wiki):

su - zimbra
zmcontrol -v

Whether the vulnerable configuration is active can be checked as follows, based on SecureLayer7’s analysis:

su - zimbra
zmlocalconfig snmp_notify
zmswatchctl status
grep dosnmp /opt/zimbra/conf/swatchrc
Options explained
OptionEffect
su - zimbraswitches to the zimbra user with that user’s environment
zmlocalconfig snmp_notifydisplays the value of the snmp_notify parameter; true means SNMP notifications are active
zmswatchctl statusdisplays whether swatchdog is running
grep dosnmp /opt/zimbra/conf/swatchrcshows the location in the generated swatchdog configuration where the SNMP notification is triggered

If snmp_notify is set to true and swatchdog is active, the server is vulnerable on a version prior to 10.1.20.

What is known about the exploitation

Microsoft describes the sequence as follows: swatchdog monitors /var/log/zimbra.log and triggers an SNMP trap when service statuses change. Shell metacharacters reach this processing through a crafted SMTP request; upon a status change, swatchdog incorporates the attacker-controlled value into a call to snmptrap, which runs through a shell. The commands run with the privileges of the zimbra service account.

Timeline according to the Sources:

  1. June 26, 2026: Zimbra reports the vulnerability in a security advisory with a temporary mitigation.

  2. July 20, 2026: ZCS 10.1.20 is released with the permanent fix.

  3. July 28 through August 7, 2026: Microsoft observes probing of the injection point using two different tools.

  4. August 13, 2026: The CVE entry is published.

  5. August 17, 2026: CERT Polska warns of an active campaign and publishes checking guidance.

  6. August 21, 2026: CISA adds the vulnerability to the KEV catalog, with a deadline of August 24, 2026.

  7. September 30, 2026: Microsoft publishes an analysis of the attacks with indicators.

According to Help Net Security, the Shadowserver Foundation counted 155 compromised Zimbra instances on the internet on August 20, 2026, rising to 274 a few days later. More than 8,200 instances had not been updated at that time, although not all of them had the vulnerable SNMP configuration.

After exploitation, according to Microsoft, the attackers deployed JSP web shells in several Jetty and mailboxd directories, established persistence through a systemd service, Cron entries, and SSH keys, and gained root privileges by manipulating the PAM configuration. They read credentials using zmlocalconfig -s, queried the zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret attributes via LDAP, archived the mail store with tar, and attempted exfiltration to Azure Blob Storage via AzCopy; according to Microsoft, it has not been confirmed whether the transfer was completed. Microsoft also identifies a coin miner. The party behind the attacks is unknown.

Immediate actions

  1. Determine the version and configuration using zmcontrol -v, zmlocalconfig snmp_notify, and zmswatchctl status (see above).

  2. Check for compromise and preserve logs before making changes so analysis remains possible (see next section).

  3. Update to ZCS 10.1.20 or later. Zimbra, CERT Polska, CISA, and Microsoft all recommend this. Installations on older branches must move to 10.1.20 or later.

  4. Implement the workaround until the update: Microsoft recommends uninstalling the zimbra-snmp package or disabling SNMP notifications. The commands are listed below.

  5. Reduce exposure: According to Microsoft, restrict SNMP and SMTP to trusted hosts where mail operations allow it. SMTP remains reachable on an MTA that receives mail from the internet; in that case, updating or applying the workaround are the effective measures.

To disable SNMP notifications, SecureLayer7 provides the following commands to run as the zimbra user:

zmlocalconfig -e snmp_notify=false
zmswatchctl stop
Options explained
OptionEffect
zmlocalconfig -e snmp_notify=falsesets the snmp_notify parameter in the local configuration to false and disables SNMP notifications
zmswatchctl stopstops the swatchdog service

Afterward, SNMP traps will be unavailable for service failures; monitoring should be handled another way until the update.

Checking for compromise

The vulnerability was exploited before many systems were updated. Updating to 10.1.20 closes the attack path but does not remove web shells, systemd services, or SSH keys that have already been deployed. Microsoft explicitly recommends searching for redundant persistence and rotating Zimbra authentication keys.

Logs and directories according to CERT Polska

CERT Polska identifies two checks:

  1. /var/log/zimbra.log for entries in the form of Service status change: [Payload] changed from stopped to running or changed from running to stopped where suspicious strings appear in place of the service name.

  2. Files created by the zimbra user within the last 30 days in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/. Hive Security provides the following for this:

find /opt/zimbra/jetty/webapps /opt/zimbra/jetty_base/webapps /tmp -user zimbra -mtime -30 -ls
Options explained
OptionEffect
-user zimbraonly files owned by the zimbra user
-mtime -30only files modified in the last 30 days
-lsoutputs details such as permissions, owner, size, and timestamps

Since the attacks reportedly began as early as late July, according to Microsoft, a period longer than 30 days may be appropriate.

Additional traces according to Microsoft

AreaWhat to check
Web shellsJSP files and compiled artifacts (*_jsp.java) in the jetty_base/webapps/, jetty/webapps/, mailboxd/webapps/, and work/zimbra/jsp/ paths under /opt/zimbra
systemdzimlog.service service in /etc/systemd/system/, as well as units with unexpected owners, enabled status, or timestamps
CronEntries containing * * * * * or @reboot
SSHChanges to authorized_keys, access to /opt/zimbra/.ssh/zimbra_identity
Privilege escalationChanges to /etc/pam.d/sudo, NOPASSWD entries in /etc/sudoers.d/, zmmailboxd.out as a symbolic link to a PAM configuration
Data exfiltration/opt/zimbra/final.tar.gz archive, AzCopy download
ProcessesCalls to snmptrap followed by shell metacharacters and a call to wget or curl, ending with a # comment

Network indicators

The addresses are written in defanged form as in the Microsoft analysis.

IndicatorMeaning according to Microsoft
117.107.25[.]243:7071C2 for the dropper, delivers de.sh
192.255.193[.]111:9004C2 of the coin miner
psk1zim[.]abrdns[.]com/agentwsWebSocket channel of zimclient2
transzimbra[.]linkpc[.]netC2 for the dropper

File hashes (SHA-256)

FileSHA-256
de.shdee5af1c0f76b45d28bafd6e60c07bb8e391d98addf81ef8f13d073acdb3c48a
agent2.sh6ab7de2509038edf580aef6229c1c3db17f4da8f2d7d940818faf617d1938244
zimdown2bf28f38122bf20d5fac969cc414daa6a890cdea872d389ca93d2092b6b7773cf
zimclient2b594a42b8f1c6f090327bb9a3361c2d3515537fb7ac8da6b9061b9a3f330e159

If you find something

A match means the system is considered compromised. Preserve logs and affected files before deleting anything. Because the attackers reportedly gained root privileges and established persistence in multiple locations, according to Microsoft, rebuilding on 10.1.20 or later is safer than removing individual files. Then rotate the exposed secrets: the values from zmlocalconfig -s (including LDAP and database passwords), zimbraPreAuthKey, zimbraAuthTokenKey, and the SSH keys of the zimbra user. According to Microsoft, zimbraTwoFactorAuthSecret was also queried; users’ two-factor registrations should therefore be set up again. For multi-server installations, the check applies to all nodes, as Microsoft reports that the attackers identified mailbox and MTA servers with zmprov and used the SSH key to move between servers.

Context

Affected organizations are those that operate Zimbra as their own mail server and accept mail directly from the internet. The vulnerability is reachable through regular mail receipt, without authentication and without any user interaction. The limitation to zimbra-snmp with active notifications reduces the number of attackable systems; however, anyone who has configured SNMP monitoring is in exactly this configuration. According to SecurityWeek, CISA lists 18 Zimbra vulnerabilities in the KEV catalog, four of them from 2026; previous campaigns against Zimbra have been attributed to state-sponsored groups and financially motivated criminals. CERT-FR reported the vulnerability on August 19, 2026, together with three other CVEs fixed in Zimbra. No advisory from Switzerland’s NCSC regarding CVE-2026-73570 was available at the time of research.

Sources

  1. Zimbra: Security Advisories

    Entry on the command injection in SNMP monitoring, fixed in 10.1.20.

    https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
  2. Zimbra Blog: Patch Release Update: Zimbra 10.1.20

    Release of July 20, 2026, permanent fix for the vulnerability reported on June 26, 2026.

    https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
  3. Zimbra: Zimbra Releases/10.1.20

    Release notes with all security fixes in the version.

    https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20
  4. NVD: CVE-2026-73570

    Description, CVSS vector, CWE-78, affected versions, KEV data.

    https://nvd.nist.gov/vuln/detail/CVE-2026-73570
  5. CISA: CISA Adds One Known Exploited Vulnerability to Catalog
  6. CISA: Known Exploited Vulnerabilities Catalog, CVE-2026-73570
  7. CERT Polska: Actively exploited vulnerability in Zimbra Collaboration Suite

    Warning of August 17, 2026, with prerequisites and guidance for checking logs and directories.

    https://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/
  8. Microsoft Security Blog: Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
  9. CERT-FR: CERTFR-2026-AVI-1041

    Advisory of August 19, 2026, on multiple vulnerabilities in Zimbra prior to 10.1.20.

    https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1041/
  10. HKCERT: Zimbra Multiple Vulnerabilities

    Bulletin with affected versions and notice of active exploitation.

    https://www.hkcert.org/security-bulletin/zimbra-multiple-vulnerabilities_20260824
  11. SecureLayer7: CVE-2026-73570: Zimbra Swatchdog SNMP Command Injection

    Technical analysis of the cause, commands for checking and the workaround.

    https://blog.securelayer7.net/cve-2026-73570-zimbra-command-injection/
  12. Hive Security: Zimbra CVE-2026-73570: Patch the Mail Server, Then Prove It Wasn’t Already Owned

    Search command for the directories identified by CERT Polska.

    https://hivesecurity.gitlab.io/blog/zimbra-cve-2026-73570-snmp-rce-compromise-triage/
  13. Help Net Security: Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

    Shadowserver Foundation figures on compromised and non-updated instances.

    https://www.helpnetsecurity.com/2026/08/25/zimbra-cve-2026-73570-compromised/
  14. The Hacker News: Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

    Summary with the KEV deadline and checking guidance from CERT Polska.

    https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html
  15. BleepingComputer: Critical Zimbra RCE flaw now actively exploited in attacks

    Report on exploitation and the number of internet-accessible Zimbra servers.

    https://www.bleepingcomputer.com/news/security/critical-zimbra-rce-flaw-now-actively-exploited-in-attacks/
  16. SecurityWeek: Hackers Target Zimbra Servers in Active Exploitation Campaign

    Context including the number of Zimbra vulnerabilities in the KEV catalog.

    https://www.securityweek.com/hackers-target-zimbra-servers-in-active-exploitation-campaign/
  17. Zimbra Wiki: Zmcontrol

    Documentation for zmcontrol -v for checking the version.

    https://wiki.zimbra.com/wiki/Zmcontrol

Comments

Comments are loaded from GitHub / Giscus.