CVE-2026-73570
Published Aug 13, 2026
Last updated 12 hours ago
AI description
CVE-2026-73570 is a remote code execution vulnerability identified in Zimbra Collaboration (ZCS) versions prior to 10.1.20. This flaw specifically impacts systems where the optional `zimbra-snmp` package is installed and SNMP notifications are enabled. The vulnerability arises from inadequate sanitization of untrusted input during the processing of SNMP notifications. An unauthenticated attacker can exploit this by sending specially crafted SMTP requests, which can lead to the execution of arbitrary operating system commands with the privileges of the Zimbra user. This vulnerability has been actively exploited in the wild.
- Description
- A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- zimbra_collaboration_suite
CVSS 3.1
- Type
- Secondary
- Base score
- 8.9
- Impact score
- 6
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Exploit added on
- Aug 21, 2026
- Exploit action due
- Aug 24, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- cve@mitre.org
- CWE-78
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
11
🚨 CISA Warns of Actively Exploited Zimbra RCE Vulnerability CISA has added CVE-2026-73570, a high-severity remote code execution vulnerability affecting Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities catalog following evidence of active exploitation.
@DailyDarkWeb
24 Aug 2026
4023 Impressions
1 Retweet
8 Likes
3 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-73570: Zimbra Collaboration Suite Actively Exploited — CISA KEV Additi… "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570,…" 🔗 https://t.co/48dM85osu2 #CyberSecurity #ThreatIntel #cve #zeroday
@SecurityAr58409
24 Aug 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA says Zimbra CVE-2026-73570 is actively exploited. If ZCS runs `zimbra-snmp` with notifications enabled, upgrade to 10.1.20+ and review SMTP-to-process anomalies today. Federal due date: Aug. 24. https://t.co/GvKKA6SVBY
@isectech_
23 Aug 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-73570: Zimbra Collaboration unauthenticated RCE via Swatchdog/SNMP log-injection command injection swatchrc dosnmp Perl backtick https://t.co/sruc1kqRGb #pruva
@N3mes1s
23 Aug 2026
2339 Impressions
11 Retweets
38 Likes
23 Bookmarks
0 Replies
0 Quotes
CISA added CVE-2026-73570 to KEV after exploitation of Zimbra was confirmed. The scope is narrower than the headline: ZCS before 10.1.20 is affected when zimbra-snmp is installed and SNMP notifications are enabled. That's the first exposure check I'd run.
@NeriaBasha
23 Aug 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Zimbra CVE-2026-73570 is under active exploitation. If SNMP notifications are enabled, patch to 10.1.20+ and hunt the published log and file indicators. https://t.co/CglpQNXV8t
@AiCybr_
23 Aug 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added Zimbra CVE-2026-73570 to its exploited-vulnerability catalog. The flaw can turn crafted SMTP requests into commands as the Zimbra user. Patch to a fixed release, then inspect the host. An upgrade doesn't prove it wasn't compromised. https://t.co/WhQkVXHsF0
@CX1Dev
23 Aug 2026
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA Adds Zimbra OS Command Injection CVE-2026-73570 to KEV Catalog — CISA has added CVE-2026-73570, an OS command injection vulnerability in… https://t.co/yVZcBM5aNo #Cybersecurity #SecOps #VulnerabilityManagement
@VettedSecOps
22 Aug 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ KEV SIGNAL Zimbra CVE-2026-73570 is in CISA KEV. With optional SNMP notifications enabled, crafted SMTP can trigger OS commands. ⚠️ Upgrade to 10.1.20+; assess exposure. https://t.co/FAkme7YxXQ
@supernovanomad
22 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CYBER BULLETIN | 2026/08/22 🚨 1. CISA adds Zimbra OS command injection to KEV catalog CVE-2026-73570 is under active exploitation. Unauthenticated attackers can execute commands as the Zimbra user via crafted SMTP requests when SNMP notifications are enabled. Email se
@FrontieraTechIT
22 Aug 2026
74 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CVE-2026-73570: Zimbra Collaboration Suite Command Injection Added to CISA KEV … "On August 21, 2026, CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/Gz5Qo1PoBZ #CyberSecurity #ThreatIntel #cve #zeroday
@SecurityAr58409
22 Aug 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-73570, an actively exploited OS command injection flaw in Zimbra Collaboration Suite, hits default installs where swatchdog runs. #DFIR_Radar https://t.co/GhiTh2viEv
@DFIR_Radar
22 Aug 2026
99 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Zimbra Collaboration SuiteにOSコマンドインジェクション — CVE-2026-73570がCISA KEVに登録、修正版10.1.20への更新を呼びかけ https://t.co/SIZ4ZcQiR8
@NEXSIGHTNEWS
22 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔐 Daily Security & Standards Brief (Aug 21) CVE-2026-73570--Zimbra Collaboration Suite (ZCS): sanitize inputs and patch Zimbra Collaboration Suite (ZCS). Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/xONex7NVHA
@PCMedicalist
22 Aug 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 Zimbra Collaboration, Command Injection, #CVE-2026-73570 (HIGH) -DC-Aug2026-1752 https://t.co/pkpPhN5hAv
@dailycve
22 Aug 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-08-21 CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability CVSS 8.9 · EPSS 0.5% · 3 public exploits Details, versions & intel → https://t.co/W3e1OUv1nt https://t.co/B2lllNZVfI
@notCVE
22 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Zimbra ZCS <10.1.20 has an exploited RCE (CVE-2026-73570, KEV Aug 21, due Aug 24): crafted SMTP mail triggers the SNMP notification handler, running OS commands as the Zimbra user — but only with the optional zimbra-snmp package installed. Upgrade; audit which hosts carry it
@SystemArch_AI
22 Aug 2026
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CVE-2026-73570: Inyección de Comandos OS en Zimbra ZCS Explotada Activamente | Análisis Técnico CVE-2026-73570 en Zimbra ZCS permite ejecución remota de comandos vía SMTP sin autenticación. CVSS 8.9. Análisis técnico y mitigaciones. https://t.co/48N47Uu6de #ciber
@CiberPlanetaOrg
21 Aug 2026
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ Alerta de Seguridad: Zimbra Collaboration Suite OS Command Injection sin autenticación (CVE-2026-73570) Inyección de comandos OS en Zimbra ZCS vía SMTP permite RCE sin autenticación como usuario Zimbra. CVSS 8.9. Fecha límite FCEB: 2026-08-24. https://t.co/nY8dZLuHH2
@CiberPlanetaOrg
21 Aug 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Zimbraの未認証リモートコード実行(RCE)脆弱性(CVE-2026-73570、CVSS 8.9)が野生下で悪用中 CVE-2026-73570 Exploited in the Wild: Unauthenticated RCE Hits Zimbra #DailyCyberSecurity (Aug 20) https://t.co/TDAX85usd2
@foxbook
21 Aug 2026
288 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-73570 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications ar… https://t.co/3LsstiQa3e ----- Traducción: CVE-2026-73570 Exi… https://t.co/bYtskK
@infoflowcloud
13 Aug 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2DA7AB29-C275-4B2D-AC7F-288B3121779F",
"versionEndExcluding": "10.1.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]