← back
CVE-2026-73570highunder attackCWE-78

CVE-2026-73570

91Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.9epss 21%
from disclosure to weapon8 days
Published on NVDAug 13
1st PoC+8d
CISA KEV+8d
exploitation probability
21%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
8 public exploit(s)
Action required by CISAfederal deadline: 2026-08-24

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

Zimbra Collaboration has a vulnerability in its optional SNMP notification feature that allows attackers to run unauthorized commands on the server by sending specially crafted requests, without needing a password.

Technical detail

CWE-78 command injection vulnerability in SNMP notification processing allows unauthenticated remote attackers to execute arbitrary OS commands as the Zimbra process user via unsanitized input in crafted SMTP requests. Impact requires the optional zimbra-snmp package to be installed with SNMP notifications enabled.

Summary generated and translated by AI from the official description.
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Affected products
Zimbra · Collaboration
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.