Microsoft details CVE-2026-73570: unauthenticated command injection hitting mail servers

yuridiogenes · x · 2026-10-01

Microsoft Threat Intelligence detailed exploitation of CVE-2026-73570, an unauthenticated OS command injection in internet-facing mail servers exploitable without authentication or user interaction.

Successful exploitation enabled webshell deployment, reverse shells, privilege escalation, persistent remote-access tooling, and theft of credentials and mailbox data, with both automated payload delivery and hands-on-keyboard activity observed.

Analysis of confirmed compromises revealed multiple attack paths and pre-disclosure reconnaissance targeting the same injection path before public disclosure. The full research covers technical details, detection opportunities, and mitigation guidance.

Original post →

More from Safety

Safety channel →