CVE-2026-73570

Published Aug 13, 2026

Last updated 12 hours ago

Exploit knownCVSS high 8.9
Zimbra Collaboration
ZCS

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-73570 is a remote code execution vulnerability identified in Zimbra Collaboration (ZCS) versions prior to 10.1.20. This flaw specifically impacts systems where the optional `zimbra-snmp` package is installed and SNMP notifications are enabled. The vulnerability arises from inadequate sanitization of untrusted input during the processing of SNMP notifications. An unauthenticated attacker can exploit this by sending specially crafted SMTP requests, which can lead to the execution of arbitrary operating system commands with the privileges of the Zimbra user. This vulnerability has been actively exploited in the wild.

Description
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Source
cve@mitre.org
NVD status
Analyzed
Products
zimbra_collaboration_suite

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Exploit added on
Aug 21, 2026
Exploit action due
Aug 24, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

cve@mitre.org
CWE-78

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

11

  1. 🚨 CISA Warns of Actively Exploited Zimbra RCE Vulnerability CISA has added CVE-2026-73570, a high-severity remote code execution vulnerability affecting Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities catalog following evidence of active exploitation.

    @DailyDarkWeb

    24 Aug 2026

    4023 Impressions

    1 Retweet

    8 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  2. 🔒 #CyberSecurity CVE-2026-73570: Zimbra Collaboration Suite Actively Exploited — CISA KEV Additi… "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570,…" 🔗 https://t.co/48dM85osu2 #CyberSecurity #ThreatIntel #cve #zeroday

    @SecurityAr58409

    24 Aug 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CISA says Zimbra CVE-2026-73570 is actively exploited. If ZCS runs `zimbra-snmp` with notifications enabled, upgrade to 10.1.20+ and review SMTP-to-process anomalies today. Federal due date: Aug. 24. https://t.co/GvKKA6SVBY

    @isectech_

    23 Aug 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-73570: Zimbra Collaboration unauthenticated RCE via Swatchdog/SNMP log-injection command injection swatchrc dosnmp Perl backtick https://t.co/sruc1kqRGb #pruva

    @N3mes1s

    23 Aug 2026

    2339 Impressions

    11 Retweets

    38 Likes

    23 Bookmarks

    0 Replies

    0 Quotes

  5. CISA added CVE-2026-73570 to KEV after exploitation of Zimbra was confirmed. The scope is narrower than the headline: ZCS before 10.1.20 is affected when zimbra-snmp is installed and SNMP notifications are enabled. That's the first exposure check I'd run.

    @NeriaBasha

    23 Aug 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Zimbra CVE-2026-73570 is under active exploitation. If SNMP notifications are enabled, patch to 10.1.20+ and hunt the published log and file indicators. https://t.co/CglpQNXV8t

    @AiCybr_

    23 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CISA added Zimbra CVE-2026-73570 to its exploited-vulnerability catalog. The flaw can turn crafted SMTP requests into commands as the Zimbra user. Patch to a fixed release, then inspect the host. An upgrade doesn't prove it wasn't compromised. https://t.co/WhQkVXHsF0

    @CX1Dev

    23 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CISA Adds Zimbra OS Command Injection CVE-2026-73570 to KEV Catalog — CISA has added CVE-2026-73570, an OS command injection vulnerability in… https://t.co/yVZcBM5aNo #Cybersecurity #SecOps #VulnerabilityManagement

    @VettedSecOps

    22 Aug 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🛡️ KEV SIGNAL Zimbra CVE-2026-73570 is in CISA KEV. With optional SNMP notifications enabled, crafted SMTP can trigger OS commands. ⚠️ Upgrade to 10.1.20+; assess exposure. https://t.co/FAkme7YxXQ

    @supernovanomad

    22 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🛡️ CYBER BULLETIN | 2026/08/22 🚨 1. CISA adds Zimbra OS command injection to KEV catalog CVE-2026-73570 is under active exploitation. Unauthenticated attackers can execute commands as the Zimbra user via crafted SMTP requests when SNMP notifications are enabled. Email se

    @FrontieraTechIT

    22 Aug 2026

    74 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. 🔒 #CyberSecurity CVE-2026-73570: Zimbra Collaboration Suite Command Injection Added to CISA KEV … "On August 21, 2026, CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/Gz5Qo1PoBZ #CyberSecurity #ThreatIntel #cve #zeroday

    @SecurityAr58409

    22 Aug 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2026-73570, an actively exploited OS command injection flaw in Zimbra Collaboration Suite, hits default installs where swatchdog runs. #DFIR_Radar https://t.co/GhiTh2viEv

    @DFIR_Radar

    22 Aug 2026

    99 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. Zimbra Collaboration SuiteにOSコマンドインジェクション — CVE-2026-73570がCISA KEVに登録、修正版10.1.20への更新を呼びかけ https://t.co/SIZ4ZcQiR8

    @NEXSIGHTNEWS

    22 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🔐 Daily Security & Standards Brief (Aug 21) CVE-2026-73570--Zimbra Collaboration Suite (ZCS): sanitize inputs and patch Zimbra Collaboration Suite (ZCS). Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/xONex7NVHA

    @PCMedicalist

    22 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🔴 Zimbra Collaboration, Command Injection, #CVE-2026-73570 (HIGH) -DC-Aug2026-1752 https://t.co/pkpPhN5hAv

    @dailycve

    22 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. ⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-08-21 CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability CVSS 8.9 · EPSS 0.5% · 3 public exploits Details, versions & intel → https://t.co/W3e1OUv1nt https://t.co/B2lllNZVfI

    @notCVE

    22 Aug 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Zimbra ZCS <10.1.20 has an exploited RCE (CVE-2026-73570, KEV Aug 21, due Aug 24): crafted SMTP mail triggers the SNMP notification handler, running OS commands as the Zimbra user — but only with the optional zimbra-snmp package installed. Upgrade; audit which hosts carry it

    @SystemArch_AI

    22 Aug 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🛡️ CVE-2026-73570: Inyección de Comandos OS en Zimbra ZCS Explotada Activamente | Análisis Técnico CVE-2026-73570 en Zimbra ZCS permite ejecución remota de comandos vía SMTP sin autenticación. CVSS 8.9. Análisis técnico y mitigaciones. https://t.co/48N47Uu6de #ciber

    @CiberPlanetaOrg

    21 Aug 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🛡️ Alerta de Seguridad: Zimbra Collaboration Suite OS Command Injection sin autenticación (CVE-2026-73570) Inyección de comandos OS en Zimbra ZCS vía SMTP permite RCE sin autenticación como usuario Zimbra. CVSS 8.9. Fecha límite FCEB: 2026-08-24. https://t.co/nY8dZLuHH2

    @CiberPlanetaOrg

    21 Aug 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Zimbraの未認証リモートコード実行(RCE)脆弱性(CVE-2026-73570、CVSS 8.9)が野生下で悪用中 CVE-2026-73570 Exploited in the Wild: Unauthenticated RCE Hits Zimbra #DailyCyberSecurity (Aug 20) https://t.co/TDAX85usd2

    @foxbook

    21 Aug 2026

    288 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨*CVE* CVE-2026-73570 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications ar… https://t.co/3LsstiQa3e ----- Traducción: CVE-2026-73570 Exi… https://t.co/bYtskK

    @infoflowcloud

    13 Aug 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations