Hackers began exploiting a high-severity OS command injection in Zimbra Collaboration Suite (ZCS) shortly after patches shipped — but before the vulnerability went public. That is Microsoft's finding as summarised by SecurityWeek on 1 October 2026. The flaw, CVE-2026-73570 at CVSS 8.9, stems from untrusted input during SNMP notification processing not being properly sanitised in ZCS before 10.1.20.
If the `zimbra-snmp` package is installed and SNMP notifications are enabled, an attacker can under certain conditions trigger the defect via specially crafted emails without user interaction (SMTP). The patch shipped on 20 July in ZCS 10.1.20; public disclosure followed on 13 August. Microsoft observed two distinct out-of-band scanning tools probing the injection point between 28 July and 7 August — the window between fix and public information. Poland's CERT Polska flagged active exploitation and released IOCs on 17 August.
The pattern is familiar for email infrastructure: "patch available but not disclosed" leaves an exploitation window against organisations that do not follow vendor embargo channels. Zimbra is common in universities, municipalities and smaller enterprises across Europe — including the Nordics — where SNMP add-ons may have been installed for monitoring without security teams prioritising them.
Concrete steps
1. Upgrade ZCS to 10.1.20 or later immediately. 2. If patching is delayed: uninstall `zimbra-snmp` or disable SNMP notifications. 3. Restrict SNMP and SMTP access; hunt CERT Polska IOCs since July. 4. Review mail servers for unusual processes tied to SNMP notification. 5. Subscribe to Zimbra security channels so pre-disclosure patches are caught.
Evidence Rail
- Confirmed: Microsoft on scanning 28 Jul–7 Aug; patch 20 Jul; disclosure 13 Aug; CERT Polska IOCs 17 Aug; CVSS 8.9.
- Reported: SecurityWeek 1 October.
- Unconfirmed: Attribution and count of compromised instances.
Organisations in Sweden, Norway, Denmark and Finland that expose affected systems to the internet or rely on them in critical workflows should treat this disclosure as an operational priority. Map access, patch windows and accountable owners within 24 hours. Document compensating controls if immediate upgrade is impossible, and ensure SOC receives hunting guidance the same day. For leadership: tie the risk to business continuity, regulatory duties and insurance terms — not only to the IT ticket queue. Log remediation timestamps so due diligence can be shown later.
In Brief
- Zimbra SNMP command injection exploited between patch and public disclosure.
- Needs zimbra-snmp + SNMP notices; can be triggered via email.
- Upgrade to 10.1.20+ or disable SNMP notification.
For Nordic organisations rapid inventory, documented patch status and clear escalation to leadership are essential — both for incident readiness and to show due diligence to regulators and insurers.
For Nordic organisations rapid inventory, documented patch status and clear escalation to leadership are essential — both for incident readiness and to show due diligence to regulators and insurers.
Organisations in Sweden, Norway, Denmark and Finland that expose affected systems to the internet or rely on them in critical workflows should treat this disclosure as an operational priority. Map access, patch windows and accountable owners within 24 hours. Document compensating controls if immediate upgrade is impossible, and ensure SOC receives hunting guidance the same day. For leadership: tie the risk to business continuity, regulatory duties and insurance terms — not only to the IT ticket queue. Log remediation timestamps so due diligence can be shown later.