Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-01 · updated: 2026-10-01 · tags: [incident, government] · confidence: high · severity: high · affected_sectors: [government] · au_impact: true

Microsoft Security Research published findings on attackers weaponising CVE-2026-73570 (CVSS 8.9), an unauthenticated operating system command injection flaw in Zimbra Collaboration Suite that becomes exploitable when SNMP notifications are enabled and the optional zimbra-snmp package is installed — an unusual precondition that narrows the exposed population to servers deliberately configured for monitoring. Exploitation is triggered by a crafted SMTP request against an exposed server, with no authentication or user interaction required. Zimbra patched it in July 2026 in version 10.1.20. Microsoft observed JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling and memory-backed execution, and says attackers accessed email and collected authentication and mailbox data, with archive creation and transfer activity following; affected organisations span more than one region and industry, though not every host showed every stage. Observed activity sits between 20 July and 13 August 2026, with two out-of-band scanning tools probing the injection path between 28 July and 7 August before payloads followed. CERT Polska first flagged exploitation in August, and CISA added the flaw to KEV with a 24 August remediation deadline; attribution is not established.

Attribute Detail
Sector Government
Date 2026-10-01
Source Microsoft Security Blog
Reliability Tier 1
CVEs CVE-2026-73570