What the technical report establishes
Microsoft describes exploitation of CVE-2026-73570 through Zimbra’s SNMP notification path when the optional package and notifications are enabled. Observed compromises included web shells, credential collection, and persistence. The report is dated 30 September; the described activity includes July and August. Microsoft’s investigation.
Security posture: the mail gateway is not the whole control
Editorial assessment: a message can interact with server-side processing before any employee opens it. Investigations need a shared timeline across mail flow, host execution, identity, and network traffic.
Verify the deployed version and optional components against current vendor guidance. If compromise is established, review service and cluster trust with the incident-response team; resetting individual mailbox passwords may leave other administrative access intact. Keep patching and compromise assessment as separate workstreams.
Which teams should act
| Team | Practical next step |
|---|---|
| Email security | Identify relevant mail servers and preserve mail-processing records; do not assume a user click is required. |
| IT operations | Record versions, optional components, configuration and remediation evidence. |
| EDR | Confirm sensor coverage on Linux mail nodes and investigate process, file and persistence evidence. |
| SIEM / SOC | Correlate host events with DNS, firewall and authentication records across the cluster. |
| Legal / privacy | Establish mailbox and authentication-data exposure from evidence, not merely the presence of the CVE. |
Sourced IOC subset
The Microsoft report lists these network leads. They are a subset, not a complete detection strategy: transzimbra[.]linkpc[.]net, psk1zim[.]abrdns[.]com, tls[.]psk1zim[.]abrdns[.]com, wslogzimbra[.]linkpc[.]net, 45.32.30[.]235, and 193.42.40[.]135. Keep the report date and context with imports; do not browse attacker infrastructure.
KQL and Splunk hunt
Illustrative and not executed in a live environment. KQL requires Defender for Endpoint telemetry in DeviceNetworkEvents for the selected server. RemoteUrl must contain a hostname for these exact comparisons. SPL assumes normalized src_ip, dest_ip, dest_port, dest_host, and action fields; verify them against a known network event. Replace every placeholder. Both searches cover seven recent days, not the historical July–August window.
// Defender XDR; replace with the onboarded Zimbra DeviceName.
let MailServer = "REPLACE_WITH_ZIMBRA_DEVICE_NAME";
DeviceNetworkEvents
| where Timestamp >= ago(7d)
| where DeviceName =~ MailServer
| where RemoteIP in ("45.32.30.235", "193.42.40.135")
or RemoteUrl in~ ("transzimbra.linkpc.net", "psk1zim.abrdns.com",
"tls.psk1zim.abrdns.com", "wslogzimbra.linkpc.net")
| project Timestamp, DeviceName, ActionType, RemoteIP, RemotePort, RemoteUrl,
InitiatingProcessFileName, InitiatingProcessAccountName
| order by Timestamp desc
| take 200
index=YOUR_NETWORK_INDEX src_ip="YOUR_ZIMBRA_IP" earliest=-7d latest=now
| where in(dest_ip, "45.32.30.235", "193.42.40.135")
OR in(lower(dest_host), "transzimbra.linkpc.net", "psk1zim.abrdns.com",
"tls.psk1zim.abrdns.com", "wslogzimbra.linkpc.net")
| table _time src_ip dest_ip dest_port dest_host action
| sort -_time
| head 200
A hit can be an attempted or blocked connection, a security test, or traffic to reassigned infrastructure. Inspect process and action context. No match cannot clear the server: coverage gaps, altered infrastructure, URL-form fields, and other attacker behaviors are outside this search. Defender XDR table schema; Splunk evaluation functions.
Reporting note
The Hacker News coverage and the primary report are dated 30 September. Exact publication times were not verified. This is adjacent-date research from the review ending 1 October 2026, 14:42 UTC, not a confirmed rolling-24-hour disclosure. The original activity is older.