CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

Published Aug 13, 2026
·
Updated

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Other sources

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

CISA

Affected Software

3 affected components
Zimbra Zimbra Collaboration (ZCS)<10.1.20
Synacor Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite<10.1.20

Event History

Aug 13, 2026
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:19 PM
DescriptionSeverityWeaknessAffected Software
Aug 20, 2026
News Published
via BleepingComputer·09:46 AM
News Published
via BleepingComputer·09:48 AM
Aug 21, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Aug 24, 2026
News Published
via BleepingComputer·10:45 AM
Aug 25, 2026
News Published
via BleepingComputer·12:04 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-73570?

The severity of CVE-2026-73570 is high with a CVSS score of 8.9.

2

How can I fix CVE-2026-73570?

To mitigate CVE-2026-73570, upgrade to Zimbra Collaboration version 10.1.20 or later and disable the optional zimbra-snmp package if not needed.

3

What impact does CVE-2026-73570 have on systems?

CVE-2026-73570 allows an unauthenticated attacker to execute remote code on affected Zimbra Collaboration servers.

4

What conditions need to be met for CVE-2026-73570 to be exploited?

CVE-2026-73570 can be exploited when the zimbra-snmp package is installed and SNMP notifications are enabled.

5

What should I do if I can't upgrade to resolve CVE-2026-73570?

If you cannot upgrade, it is recommended to disable the zimbra-snmp package and monitor your environment for any suspicious activity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203