One Email Could Open a Mail Server. The Attackers Went After Its Master Keys

A crafted email could trigger commands on certain Zimbra servers without a click. Microsoft traced how attackers then pursued authentication keys and persistence.

A message did not need to be opened to become dangerous. Microsoft says attackers sent specially crafted email or SMTP requests to internet-facing Zimbra servers and triggered commands through a monitoring path, provided the optional zimbra-snmp package was installed and SNMP notifications were enabled. The report describes no required user click or login. It does not show that every Zimbra installation was exposed. Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 How to find Zimbra installations on your network

The route was CVE-2026-73570, an unauthenticated operating-system command-injection flaw in Zimbra Collaboration's SNMP notification path. In ordinary terms, data arriving in a monitoring message could cross a boundary and be treated as a command for the server to run. Zimbra released version 10.1.20 with the relevant fix on July 20, 2026. Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Zimbra Security Advisories Zimbra Daffodil (v10.1.20) Patch Release

The patch arrived before the public warning

Microsoft published its forensic account on September 30. It says probing was observed from July 28 through August 7, after the fix was released and before public disclosure on August 13. That timing is notable, but the report does not demonstrate how the attackers learned about the flaw or establish that the patch itself failed. Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

From one service account to the mail cluster

In the incidents Microsoft investigated, initial command execution under a Zimbra account was followed by JSP web shells and reverse shells. One escalation path moved through service helpers and PAM to root-level access. The report combines behavior across multiple confirmed compromises, so no single server should automatically be assumed to have experienced every stage. Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

The reported target was broader than individual mailbox passwords. Microsoft observed collection of centralized Zimbra service credentials and authentication attributes, including zimbraPreAuthKey and zimbraAuthTokenKey. In one case, attackers used existing Zimbra SSH trust and rsync to spread tools to peer mailbox nodes. That creates a practical human consequence: a single compromised mail server can become a route toward other systems and shared accounts. Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

A copied archive is not confirmed theft

Microsoft also describes an attempt to archive mailbox backups and invoke AzCopy toward cloud storage. Its evidence does not confirm that the transfer completed. The distinction matters: collection and staging show what attackers handled locally, while the report stops short of proving that mailbox data left the environment. Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Updating is only the first check

The durable problem is persistence. Closing the command-injection path prevents the same entry route, but it cannot by itself reveal web shells, remove other persistence or invalidate keys already collected. Microsoft advises upgrading to 10.1.20 or later, investigating for redundant shells and persistence, and rotating Zimbra authentication secrets after a suspected compromise. The report's central warning is practical rather than absolute: a patched server may still require a search for what happened before the patch took effect. Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Zimbra Daffodil (v10.1.20) Patch Release

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 399

Newsletter Updates

Enter your email address below and subscribe to our newsletter