A critical security flaw in the Zimbra Collaboration Suite (ZCS), identified as CVE-2026-73570, was exploited by hackers before it was made public. The vulnerability enables attackers to inject and run unauthorized commands on servers that have the optional zimbra-snmp package installed and SNMP notifications enabled. By sending specially crafted SMTP requests, attackers could execute system commands with the privileges of the zimbra user. A patch to fix the issue was released on July 20, but the vulnerability was not disclosed publicly until August 13. Microsoft Threat Intelligence reported that attackers had begun scanning for vulnerable systems as early as July 28, using tools that sent HTTP requests, DNS queries, ICMP pings, and other out-of-band checks. These scans used a specific User-Agent, ZB73570, suggesting that the attackers had analyzed the patch before the official CVE bulletin was published. The attackers deployed malicious JSP webshells within Zimbra's web directories, temporarily altering permissions on a public folder to bypass security checks before restoring them. They also installed a disguised systemd service, zimlog.service, with timestamps altered to resemble sshd.service. On compromised servers, hackers gained root access by hijacking Zimbra's administration tools, replacing a log file with a symbolic link to the sudo authentication configuration. This allowed them to execute commands with elevated privileges. They stole internal Zimbra service passwords, including those for LDAP and MySQL, using the zmlocalconfig command. They also extracted the zimbraAuthTokenKey, which is used to sign session tokens, allowing attackers to log in to any account without credentials. Additionally, they stole the zimbraPreAuthKey, which can be used to generate valid login URLs for any account. The attackers used the SSH identity of the Zimbra user to access other cluster nodes and copy their webshells. Microsoft researchers detected the use of the zimclient2 remote access agent, which can turn a compromised server into a SOCKS5 relay, allowing access to the internal network. In some instances, attackers used Microsoft's AzCopy tool to transfer mailbox backups to Azure storage, though it is unclear whether these transfers were successful. Microsoft recommends upgrading to Zimbra 10.1.20 or, if that is not possible, disabling the zimbra-snmp package and restricting SNMP and SMTP access to trusted hosts. Administrators are also advised to renew the zimbraPreAuthKey and zimbraAuthTokenKey and to inspect each mailbox node for unexpected JSP files. According to Microsoft, removing a single known JSP file does not guarantee the complete removal of access. The CERT-FR issued a security notice on August 20, and the U.S. CISA added the vulnerability to its list of actively exploited flaws two days later. The Shadowserver Foundation reported that 155 Zimbra servers were compromised on August 20, rising to 274 by August 22, including 21 in France. More than 8,000 instances had not yet been fixed by that date, though not all had the vulnerable SNMP configuration activated. The incident highlights the risks of delayed disclosure of critical vulnerabilities and the importance of timely patching and configuration management.