🔴 CVE-2026-73570

CVE-2026-73570 is an unauthenticated OS command injection (RCE) vulnerability in Zimbra Collaboration Suite (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An attacker can send specially crafted SMTP requests that trigger arbitrary OS command execution as the Zimbra user. This is a server-side RCE in an internet-facing mail collaboration platform, actively exploited in the wild and listed in CISA KEV.

← Back to Overview
HIGH_RISK
Risk Level
8.9
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-08-13

Added to CISA KEV: 2026-08-21 8 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-14)

Summary

CVE-2026-73570 is a critical remote code execution (RCE) vulnerability affecting Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20, specifically when the optional `zimbra-snmp` package is installed and SNMP notifications are enabled. The vulnerability stems from improper sanitization of untrusted input during the processing of SNMP notifications, which allows an unauthenticated attacker to perform OS command injection. This issue is highly significant as it provides attackers with the ability to execute arbitrary code on the underlying operating system as the Zimbra user, leading to potential full system compromise [1][2].

Exploitation

  • Active Exploitation: The vulnerability is actively exploited in the wild, with reports confirming hundreds of internet-facing Zimbra instances have been compromised [4][7].
  • Threat Actors & Campaigns: Observed malicious activity includes the deployment of coin-miner malware [3].
  • Tool Availability: The vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) Catalog due to confirmed evidence of exploitation [6].
  • Attack Prerequisites: The attack is network-based and does not require authentication or user interaction; attackers send specially crafted requests to the SNMP notification handling component [1][8].

Affected Products & Patches

  • Affected Versions: Zimbra Collaboration Suite (ZCS) versions before 10.1.20 are affected, provided the `zimbra-snmp` package is installed and SNMP notifications are enabled [2].
  • Patch Availability: A fix is available in Zimbra Collaboration version 10.1.20 and later [2].
  • Mitigations/Workarounds: If immediate patching is not possible, organizations should disable the `zimbra-snmp` service or disable SNMP notifications to mitigate the risk [5].

Impact

  • Access/Capability: Successful exploitation results in remote code execution, granting the attacker the privileges of the Zimbra service user on the host system, which can escalate to full system compromise [1].
  • Business Risk: For internet-facing deployments, this vulnerability presents an extreme risk, as it allows unauthenticated remote attackers to gain a foothold, potentially leading to data exfiltration, lateral movement within the network, or the deployment of additional malicious payloads such as ransomware or cryptominers [3][4].

Sources

  1. CVE-2026-73570 - Vulnerability Details - OpenCVE

    The vulnerability is a command-injection flaw that occurs when Zimbra’s SNMP notification system processes untrusted input. An unauthenticated attacker can send crafted SMTP requests via SNMP notifications for the optional zimbra‑snmp package, causing the Zimbra server to execute arbitrary operating…

  2. NVD-CVE-2026-73570 - National Vulnerability Database

    A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed ... CVE-2026-73570 Detail Description A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp p…

  3. Zimbra SNMP RCE abused to deploy coin-miner malware

    CVE-2026-73570 is a Remote Code Execution issue in Zimbra Collaboration Suite (ZCS), related to SNMP notification/logwatch handling.

  4. Unpatched Zimbra servers are falling to CVE-2026-73570 ...

    At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570.

  5. CVE-2026-73570 | Vulnerability Details

    Fixed a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. A remote code execution vulnerability exists ...