Vulnerability
Published 2026-08-21
Verified 2026-09-19

Zimbra Collaboration Suite SNMP command injection (CVE-2026-73570)

Unauthenticated OS command injection in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. NVD: crafted SMTP requests can run commands as the zimbra user. CERT Polska reported active exploitation. Patch to 10.1.20. If you cannot upgrade, remove zimbra-snmp / disable snmp_notify and hunt per CERT Polska.

Product
Zimbra Collaboration Suite (ZCS)
Versions
Before 10.1.20 with zimbra-snmp and snmp_notify enabled
CVSS
(CVSS 3.1, NVD)
Exploited in Australia?
unknown
Patch to
10.1.20

Primary: Zimbra Security Advisories · Vendor: NVD · CVE: CVE-2026-73570 · CERT Polska 145/2026

vulnerabilities email