Vulnerability record · CVE-2026-73570 · published 13 August 2026
CVE-2026-73570: Zimbra Collaboration SNMP notification OS command injection
SSynacor · Zimbra Collaboration Suite
Zimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Untrusted input is not properly sanitized, so crafted SMTP requests can lead to arbitrary OS command execution. The flaw matters because it is remotely reachable without authentication and is listed in CISA KEV.
Description
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Automated analysis
critical priorityThe flaw allows unauthenticated remote command execution, is listed in CISA KEV with a near-term remediation deadline, and has a high EPSS score.
What it is
Zimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Untrusted input is not properly sanitized, so crafted SMTP requests can lead to arbitrary OS command execution. The flaw matters because it is remotely reachable without authentication and is listed in CISA KEV.
Impact
An unauthenticated attacker can execute arbitrary operating system commands as the Zimbra user, giving host-level access to mail data and the Zimbra service account. The CVSS vector rates confidentiality and integrity impact as high and availability impact as low.
Attack surface
Reachable over the network via crafted SMTP requests; the CVSS vector shows no privileges required and no user interaction. Exploitation requires the optional zimbra-snmp package to be installed and SNMP notifications enabled, which narrows the exposed population.
Exploitation
CVE-2026-73570 was added to CISA KEV on 2026-08-21 with a remediation due date of 2026-08-24, indicating known exploitation. EPSS is 0.32383 (98.2nd percentile), and a third-party advisory reference describes active exploitation; no ransomware campaign use is documented.
What to do
- Upgrade Zimbra Collaboration Suite to 10.1.20 or later, following the vendor security advisories.
- If patching cannot be done immediately, disable SNMP notifications or remove the optional zimbra-snmp package where it is not required.
- Restrict network access to SMTP services so only trusted mail relays can reach Zimbra.
- Apply CISA BOD 26-04 guidance, including forensics triage requirements, for internet-exposed Zimbra assets.
- Treat any internet-facing, unpatched Zimbra host with zimbra-snmp enabled as compromised and begin incident response.
Detection
- Review Zimbra and host logs for unexpected child processes spawned by the Zimbra user, especially shell or command interpreters.
- Monitor SMTP traffic for anomalous or malformed requests that coincide with SNMP notification activity.
- Audit which Zimbra hosts have the zimbra-snmp package installed and SNMP notifications enabled.
- Hunt for outbound connections or file changes made by the Zimbra service account outside normal mail operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-73570 to the Known Exploited Vulnerabilities catalog on 21 August 2026 as "Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 24 August 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wiki.zimbra.com/wiki/Security_Center | Release Notes |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory |
| https://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570 | US Government Resource |
Track CVE-2026-73570 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-73570), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.