CVE Tools

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

In plain language

AI Act now

If you run Zimbra Collaboration and have the optional zimbra-snmp package installed with SNMP notifications turned on, you should treat CVE-2026-73570 as an urgent remote takeover risk and update to 10.1.20 or later immediately.

Executive summary

CVE-2026-73570 is a remote code execution flaw in Zimbra Collaboration via SNMP notification processing: improper sanitization of untrusted input can let an unauthenticated attacker trigger arbitrary OS command execution as the Zimbra user when zimbra-snmp is installed and SNMP notifications are enabled; it is listed in CISA KEV with an action deadline of 2026-08-24.

If affected, business impact
Full server takeoverMalware installation riskCustomer email data compromiseService outage and disruption

What to do now

  1. Check whether your Zimbra server is running Collaboration (ZCS) older than 10.1.20, and whether the optional zimbra-snmp package is installed.
  2. Verify whether SNMP notifications are enabled in your Zimbra/SNMP configuration.
  3. If both are true, plan to upgrade Collaboration to fixed version 10.1.20 (or later) using Zimbra’s official security guidance.
  4. If you cannot upgrade immediately, disable SNMP notifications and/or remove the zimbra-snmp package per vendor instructions, then confirm the change took effect.
  5. Document the date/time of the change and monitor for suspicious activity on the Zimbra host until the update is completed.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:HPR:NUI:NS:CC:HI:HA:L
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:LAvailability
Low

Weaknesses

Affected Products

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Aug 21, 2026
Remediation due:Aug 24, 2026

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

and 1 more references View all →
3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-73570 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows