CVE-2026-73570
published 2026-08-13CVE-2026-73570: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP…
PriorityP195high8.9CVSS 3.1
AVNACHPRNUINSCCHIHAL
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-08-24
Exploited in the wild
EPSS
20.53%
97.4th percentile
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| synacor | zimbra_collaboration_suite | < 10.1.20 | 10.1.20 |
| zimbra | collaboration | < 10.1.20 | 10.1.20 |
CVSS provenance
nvdv3.18.9HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
vulncheck8.9HIGH
cisa8.9HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Zimbra Collaboration up to 10.1.19 Notification code injection (WID-SEC-2026-2429)
vuldb·2026-08-16·CVSS 8.9
CVE-2026-73570 [HIGH] Zimbra Collaboration up to 10.1.19 Notification code injection (WID-SEC-2026-2429)
A vulnerability, which was classified as critical, was found in Zimbra Collaboration up to 10.1.19. The impacted element is an unknown function of the component Notification. Such manipulation leads to code injection.
This vulnerability is traded as CVE-2026-73570. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
ghsa_unreviewed·2026-08-13
CVE-2026-73570 [HIGH] CWE-78 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
VulnCheck
Zimbra collaboration Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2026·CVSS 8.9
CVE-2026-73570 [HIGH] Zimbra collaboration Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Zimbra collaboration Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Affected: Zimbra collaboration
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://moje.cert.pl/komunikaty/2026/145/aktywnie-wyk
CISA
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
cisa·2026-08-21·CVSS 8.9
CVE-2026-73570 [HIGH] CWE-78 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Vulnerability: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Affected: Synacor Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for eva
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
blogs_hackernews·2026-08-24
CVE-2026-19478 ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.
Plenty to clean up. Here’s the short version.
## ⚡ Threat of the Week
U.S. Warns of AI-Powered Attacks on Siemens PLCs — Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series program
Hackernews
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
blogs_hackernews·2026-08-20·CVSS 6.1
CVE-2026-73570 [MEDIUM] Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).
The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution.
"A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed, and SNMP notifications are enabled," according to a description of the flaw
2026-08-13
Published
2026-08-21
Added to CISA KEV
Exploited in the wild