Skip to main content
QUIETLYTIC
Vulnerability

Zimbra Collaboration Suite Command Injection (CVE-2026-73570)

CVE-2026-73570 is a CVSS 8.9 OS command injection in Zimbra Collaboration Suite via SNMP notification handling, confirmed exploited per CISA KEV.

CVE-2026-73570
Threat Level
HIGH
CVSS
8.9
Status
Active Exploitation
Confidence
High
Affected Products
Zimbra Collaboration Suite (ZCS), Zimbra Collaboration (before 10.1.20)

CVE-2026-73570 carries a CVSS 3.1 base score of 8.9 against Zimbra Collaboration Suite (ZCS), Synacor’s email and collaboration platform. NVD, CISA’s own KEV entry, and VulnCheck’s KEV feed all independently classify it as CWE-78 (OS Command Injection). CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 21, 2026, confirming real-world exploitation directly rather than through a single vendor report; VulnCheck’s KEV feed independently corroborates the same exploitation status and date.

Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.

What the flaw is

NVD’s description states two specific preconditions: the flaw requires the optional zimbra-snmp package to be installed and SNMP notifications to be enabled — neither is Zimbra’s default configuration. Under those conditions, NVD states improper sanitization of untrusted input during SNMP notification processing allows an unauthenticated attacker to send specially crafted SMTP requests that can result in arbitrary OS command execution as the Zimbra user. NVD states the issue is fixed in version 10.1.20.

Because the vulnerable code path depends on an optional package and a non-default setting, actual exposure varies significantly across Zimbra deployments — an important distinction from a flaw present in every installation regardless of configuration.

Evidence and confidence

  • High confidence — exploitation status, corroborated independently by CISA KEV and VulnCheck KEV, both dated August 21, 2026.
  • High confidence — the CWE-78 classification, independently corroborated across NVD, CISA KEV, and VulnCheck KEV.
  • Medium confidence — the CVSS 8.9 score and vector (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L), which trace to NVD alone in our current ingestion.
  • FIRST’s EPSS model scores this CVE at 0.32383, a 98.2nd percentile score as of our ingestion — among the highest in our recent KEV coverage, consistent with confirmed CISA-listed exploitation.

No field is in conflict between our sources — an unusually well-corroborated record for this batch.

Why this matters

Email and collaboration platforms are high-value targets precisely because of the sensitive correspondence and organizational data they hold, and CISA’s own confirmation of active exploitation — corroborated independently by VulnCheck — puts this squarely in the highest-priority tier of our recent coverage. The specific preconditions (optional SNMP package, non-default notification setting) mean this isn’t universal to every Zimbra deployment, but any organization that has enabled SNMP monitoring on their Zimbra infrastructure should treat this as an active, confirmed threat rather than a theoretical one.

BOD 26-04’s remediation obligation genuinely applies here for in-scope federal agencies, and the near-maximal EPSS percentile independently corroborates the urgency CISA’s own listing already establishes.

Frequently Asked Questions

What is CVE-2026-73570? A CVSS 8.9 OS command injection vulnerability (CWE-78) in Zimbra Collaboration Suite before version 10.1.20, allowing unauthenticated remote code execution via crafted SMTP requests when the optional zimbra-snmp package is installed and SNMP notifications are enabled.

Is CVE-2026-73570 being actively exploited? Yes, per two independent sources: CISA’s Known Exploited Vulnerabilities catalog and VulnCheck’s KEV feed, both dated August 21, 2026. Two-source agreement on exploitation is treated as high confidence in our evidence model.

Do I need SNMP enabled for my Zimbra server to be at risk? Yes. NVD states this requires the optional zimbra-snmp package to be installed and SNMP notifications to be enabled — neither is a default Zimbra configuration.

Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.

Which version fixes this? Version 10.1.20, per NVD.


Severity, weakness classification, mechanism, and fixed version corroborated across the National Vulnerability Database record for CVE-2026-73570 and CISA’s Known Exploited Vulnerabilities catalog entry. Additional independent confirmation from CERT Polska’s advisory on active exploitation. Zimbra’s own security center: Zimbra Security Advisories. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog
03 VulnCheck KEV

Related intelligence


Analyst tools