Skip to content
Sunday, 4 October 2026
Tenesys AI News
Subscribe

All News

TENESYS AI NEWS tracks the most important AI news and explains what changed, why it matters and whether a technology is worth testing.

#Webshell — 1 article ✕

Microsoft tracks active exploitation of unauthenticated Zimbra mail server vulnerability (CVE-2026-73570)

Microsoft Threat Intelligence documented exploitation of CVE-2026-73570, an unauthenticated OS command-injection flaw in the Zimbra Collaboration Suite's SNMP notification path. Attackers triggered it via specially crafted emails against internet-facing servers running the optional zimbra-snmp package with SNMP notifications enabled, requiring no authentication or user interaction. Post-exploitation activity included JSP webshell deployment, privilege escalation to root, persistent access, credential and mailbox theft, lateral movement across Zimbra clusters, and custom remote-access malware. Zimbra fixed the issue in version 10.1.20 (released July 20, 2026); the CVE was publicly disclosed August 13, 2026, and Microsoft observed scanning and exploitation activity during the gap between patch availability and disclosure, as well as after.

Microsoft Security