The Email Was Never Opened. Nobody Clicked Anything. The Mail Server Was Still Compromised.


Active Exploitation
Zero-Click
October 2026  ·  6 min read

The employee didn't click a link. There wasn't one. They didn't open an attachment, enter a password, or even read the message. The email simply arrived. Under one specific, vulnerable configuration, that alone was enough.


You train every employee not to open a suspicious envelope.

What happens when the mailroom itself can be triggered by the envelope just arriving, before anyone carries it upstairs?

Nearly every piece of cybersecurity advice a small business hears starts the same way: don't click the link, don't open the attachment, don't enter your password on a fake page. It's good advice. It's also advice that assumes a human has to do something wrong first. Microsoft's security research team published findings on September 30, 2026 describing a vulnerability where that assumption simply doesn't apply.

What makes this one different

Microsoft tracked active, in-the-wild exploitation of CVE-2026-73570, a flaw in Zimbra Collaboration Suite, a widely used email and collaboration platform. The vulnerability sits in how a specific optional component processes incoming mail. A specially crafted email reaching a vulnerable server could trigger command execution on that server directly, with no authentication and no action required from anyone who uses it.

You can train an employee not to open a dangerous email. You can't train a mail server not to have a vulnerability.
One important scope note: this does not mean every mail server, or even every Zimbra installation, is exposed. The flaw requires an optional add-on package with a specific notification feature turned on, not Zimbra's default configuration. It's a serious, real, actively exploited issue for the systems where that applies, not a reason to assume every inbox everywhere is at risk.

What happened once the door opened

Microsoft's research describes a full attacker playbook once initial access was achieved, not a one-off proof of concept:

1
A crafted email arrives. No link, no attachment the user needs to open, no password prompt anywhere in the chain.
2
The server itself processes the exploit. Untrusted content in the message reaches a flawed notification handler and triggers command execution, unauthenticated.
3
A foothold gets planted. Microsoft observed web shells and reverse shells installed directly on the compromised server.
4
Privileges escalate, access persists. Attackers used existing system helpers to gain higher-level access and set up disguised background services to survive a restart.
5
Mailbox and credential data is targeted. Authentication secrets, stored credentials, and mailbox contents were accessed, with evidence of attempted data exfiltration to outside storage.

The timeline is the part that should worry you most

Jul 20 Zimbra released a fix for the vulnerability Microsoft research
Jul 28 Microsoft observed active probing begin, just eight days after the patch shipped Microsoft research
Aug 13 The vulnerability was publicly disclosed, roughly two weeks after probing had already started Microsoft research
Attackers were already looking for this hole before most affected businesses even knew it had a name. A patch existing somewhere doesn't help a business that hasn't applied it, and in this case, the gap between "fixed" and "known" ran backwards from what most IT teams assume: exploitation activity started before the public disclosure that would have told anyone to go check.

The SMB translation: two different defenses for two different problems

This is the real lesson, and it's bigger than one mail server product. Employee security training, phishing awareness, multi-factor authentication, and careful clicking habits are genuinely effective defenses. They are effective against attacks that require a human to make a mistake. They do nothing against a vulnerability that attacks the technology directly, before any human is involved at all.

1

Know what mail and collaboration software your business actually runs.

If you or your IT provider can't immediately answer "are we running Zimbra, and which version," that's the first gap to close, independent of this specific vulnerability.

2

Confirm patches are applied, not just available.

A fix being released is not the same as a fix being installed. Verify the current version against what the vendor has published as patched.

3

Treat exposure scanning as a complement to training, not a substitute for it, or the other way around.

Human-focused defenses and technical exposure scanning cover different attack paths. A business strong in one and weak in the other is still exposed on the weak side.

4

Don't wait for a public disclosure date to start checking.

In this case, exploitation activity began before the vulnerability was publicly announced. Patch-and-verify cycles that wait for headlines are, by definition, already behind.

This is exactly the blind spot continuous exposure scanning is built to close: not whether your employees would click something, but whether the internet-facing systems they never interact with directly are running known-vulnerable software, patched or not. The CyberScore weighs both halves, because a business can score well on human-risk measures and still be running a server with an open door nobody's checked on.

The short version

No employee made a mistake here. No password was stolen, no link was clicked, no attachment was opened. A message simply arrived, and under one specific vulnerable configuration, arriving was the entire attack. Security training solves a different problem than this one. Both matter. Neither covers for the other.

Know whether the internet-facing systems behind your email are running known-vulnerable software right now.

View the Threat Intelligence feed → Find Out More About ThreatAngel →
TA
ThreatAngel Team AI-powered cyber risk clarity for SMBs  ·  threatangel.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.