Vulnerability
Published 2026-08-21
Verified 2026-09-19
Zimbra Collaboration Suite SNMP command injection (CVE-2026-73570)
Unauthenticated OS command injection in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. NVD: crafted SMTP requests can run commands as the zimbra user. CERT Polska reported active exploitation. Patch to 10.1.20. If you cannot upgrade, remove zimbra-snmp / disable snmp_notify and hunt per CERT Polska.
- Product
- Zimbra Collaboration Suite (ZCS)
- Versions
- Before 10.1.20 with zimbra-snmp and snmp_notify enabled
- CVSS
- (CVSS 3.1, NVD)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L - Exploited in Australia?
- unknown
- Patch to
- 10.1.20
Primary: Zimbra Security Advisories · Vendor: NVD · CVE: CVE-2026-73570 · CERT Polska 145/2026
