CVE-2026-73570 is an unauthenticated OS command injection (RCE) vulnerability in Zimbra Collaboration Suite (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An attacker can send specially crafted SMTP requests that trigger arbitrary OS command execution as the Zimbra user. This is a server-side RCE in an internet-facing mail collaboration platform, actively exploited in the wild and listed in CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-08-13
Added to CISA KEV: 2026-08-21 8 DAYS BETWEEN CVE AND KEV
CVE-2026-73570 is a critical remote code execution (RCE) vulnerability affecting Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20, specifically when the optional `zimbra-snmp` package is installed and SNMP notifications are enabled. The vulnerability stems from improper sanitization of untrusted input during the processing of SNMP notifications, which allows an unauthenticated attacker to perform OS command injection. This issue is highly significant as it provides attackers with the ability to execute arbitrary code on the underlying operating system as the Zimbra user, leading to potential full system compromise [1][2].
The vulnerability is a command-injection flaw that occurs when Zimbra’s SNMP notification system processes untrusted input. An unauthenticated attacker can send crafted SMTP requests via SNMP notifications for the optional zimbra‑snmp package, causing the Zimbra server to execute arbitrary operating…
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed ... CVE-2026-73570 Detail Description A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp p…
CVE-2026-73570 is a Remote Code Execution issue in Zimbra Collaboration Suite (ZCS), related to SNMP notification/logwatch handling.
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570.
Fixed a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. A remote code execution vulnerability exists ...