← Vulnerability feed

Vulnerability record · CVE-2026-73570 · published 13 August 2026

CVE-2026-73570: Zimbra Collaboration SNMP notification OS command injection

SSynacor · Zimbra Collaboration Suite

Zimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Untrusted input is not properly sanitized, so crafted SMTP requests can lead to arbitrary OS command execution. The flaw matters because it is remotely reachable without authentication and is listed in CISA KEV.

8.9 CVSS 3.1 High CISA KEV since 21 Aug 2026 EPSS 12% · top 4.1% CWE-78 · OS command injection
8.9CVSS 3.1 base score
12%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
24 Aug 2026Last modified by NVD

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows unauthenticated remote command execution, is listed in CISA KEV with a near-term remediation deadline, and has a high EPSS score.

What it is

Zimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Untrusted input is not properly sanitized, so crafted SMTP requests can lead to arbitrary OS command execution. The flaw matters because it is remotely reachable without authentication and is listed in CISA KEV.

Impact

An unauthenticated attacker can execute arbitrary operating system commands as the Zimbra user, giving host-level access to mail data and the Zimbra service account. The CVSS vector rates confidentiality and integrity impact as high and availability impact as low.

Attack surface

Reachable over the network via crafted SMTP requests; the CVSS vector shows no privileges required and no user interaction. Exploitation requires the optional zimbra-snmp package to be installed and SNMP notifications enabled, which narrows the exposed population.

Exploitation

CVE-2026-73570 was added to CISA KEV on 2026-08-21 with a remediation due date of 2026-08-24, indicating known exploitation. EPSS is 0.32383 (98.2nd percentile), and a third-party advisory reference describes active exploitation; no ransomware campaign use is documented.

What to do

  • Upgrade Zimbra Collaboration Suite to 10.1.20 or later, following the vendor security advisories.
  • If patching cannot be done immediately, disable SNMP notifications or remove the optional zimbra-snmp package where it is not required.
  • Restrict network access to SMTP services so only trusted mail relays can reach Zimbra.
  • Apply CISA BOD 26-04 guidance, including forensics triage requirements, for internet-exposed Zimbra assets.
  • Treat any internet-facing, unpatched Zimbra host with zimbra-snmp enabled as compromised and begin incident response.

Detection

  • Review Zimbra and host logs for unexpected child processes spawned by the Zimbra user, especially shell or command interpreters.
  • Monitor SMTP traffic for anomalous or malformed requests that coincide with SNMP notification activity.
  • Audit which Zimbra hosts have the zimbra-snmp package installed and SNMP notifications enabled.
  • Hunt for outbound connections or file changes made by the Zimbra service account outside normal mail operations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-73570 to the Known Exploited Vulnerabilities catalog on 21 August 2026 as "Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 24 August 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-73570 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45519Zimbra Collaboration postjournal service unauthenticated command executionThe postjournal service in Zimbra Collaboration Suite fails to properly neutralize input, allowing OS command injection. Because the service can be r…KEVEPSS 100%analysed9.8CVE-2022-41352Zimbra Collaboration amavis cpio path traversal arbitrary file uploadZimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-…KEVEPSS 95%analysed9.8CVE-2022-37042Zimbra Collaboration Suite mboximport auth bypass path traversal RCEZimbra Collaboration Suite 8.8.15 and 9.0 mboximport accepts a ZIP archive and extracts files without requiring an authtoken, allowing unauthenticate…KEVEPSS 92%analysed9.8CVE-2020-7796Zimbra Collaboration Suite WebEx zimlet SSRFZimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabl…KEVEPSS 84%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed9.0CVE-2023-34192Zimbra ZCS autoSaveDraft XSS enables remote code executionZimbra Collaboration Suite 8.8.15 has a cross-site scripting flaw in the /h/autoSaveDraft function. A remote authenticated attacker can inject a craf…KEVEPSS 77%analysed8.8CVE-2025-68645Zimbra Webmail Classic UI RestFilter local file inclusionZimbra Collaboration Suite 10.0 and 10.1 mishandle user-supplied parameters in the RestFilter servlet of the Webmail Classic UI, allowing local file …KEVEPSS 49%analysed7.5CVE-2022-27924Zimbra Collaboration memcache command injection via unauthenticated requestZimbra Collaboration Suite 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. The inje…KEVEPSS 85%analysed

Source: NIST National Vulnerability Database (record CVE-2026-73570), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.