CVE
CVE-2026-73570
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Exploitation IoCs 6
Domain wsweb03[.]blob[.]core[.]windows[.]net
Filename final.tar.gz
Filename localconfig.xml
Filename zimbra_identity
Filename zimlog.service
GitHub Repo aka.ms/downloadazcopy-v10-linux
MITRE ATT&CK TTPs 12
T1003 T1021.001 T1021.006 T1053.001 T1059.001 T1070.004 T1071.001 T1081 T1090 T1136 T1552 T1566
OS Credential Dumping
Credential Access
Remote Desktop Protocol
Lateral Movement
Windows Remote Management
Lateral Movement
T1053.001
PowerShell
Execution
File Deletion
Defense Evasion
Web Protocols
Command And Control
T1081
Proxy
Command And Control
Create Account
Persistence
Unsecured Credentials
Credential Access
Phishing
Initial Access