CVE-2026-73570
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- Published Aug 13, 2026
- CVSS 8.9 high
- 11.9% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure SecurityWeek ·
- Attackers have been exploiting critical Zimbra flaw to steal emails Ars Technica ·
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets The Hacker News ·
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Microsoft Threat Intelligence ·