• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-73570: unauthenticated os command injection in Synacor Zimbra Collaboration Suite (ZCS)

An unauthenticated remote attacker can send malformed SMTP traffic to Zimbra Collaboration Suite and, when the optional zimbra-snmp component is present with SNMP notifications turned on, abuse how those notifications are processed to execute operating-system commands as the Zimbra user. CVE-2026-73570 impacts ZCS 10.x releases prior to 10.1.20. Successful exploitation requires network reachability to the affected SMTP service and the zimbra-snmp/SNMP-notifications configuration; no valid account or user interaction is necessary.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
8.9HIGH
EPSS
0.11736
CWE
CWE-78
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA placed this flaw on its Known Exploited Vulnerabilities list with a short remediation window, so prioritize applying Synacor’s update or temporary mitigations on exposed Zimbra servers now.

What is CVE-2026-73570?

An unauthenticated remote attacker can send malformed SMTP traffic to Zimbra Collaboration Suite and, when the optional zimbra-snmp component is present with SNMP notifications turned on, abuse how those notifications are processed to execute operating-system commands as the Zimbra user. CVE-2026-73570 impacts ZCS 10.x releases prior to 10.1.20. Successful exploitation requires network reachability to the affected SMTP service and the zimbra-snmp/SNMP-notifications configuration; no valid account or user interaction is necessary. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Which versions of Synacor Zimbra Collaboration Suite (ZCS) are affected?

BRANCHAFFECTEDFIXED
10.xbefore 10.1.2010.1.20

Is CVE-2026-73570 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-08-21, and U.S. federal agencies were required to address it by 2026-08-24.

How to fix CVE-2026-73570

  1. Upgrade Zimbra Collaboration Suite 10.x to 10.1.20.
  2. If immediate upgrade is not possible, disable or remove the zimbra-snmp package or turn off SNMP notifications.
  3. Limit network access to the Zimbra SMTP service to trusted hosts and networks.
  4. Review logs and system activity for signs of unexpected command execution or suspicious SMTP traffic.

Frequently asked questions

Is CVE-2026-73570 being actively exploited?

CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog on 2026-08-21, requiring remediation by 2026-08-24 for federal agencies.

Which Zimbra Collaboration Suite versions are affected by CVE-2026-73570?

Zimbra Collaboration Suite 10.x releases before 10.1.20 are affected.

Is there a patch for CVE-2026-73570?

Yes. Synacor released a fix in ZCS version 10.1.20.

Does CVE-2026-73570 require authentication?

No. The issue can be triggered without credentials when zimbra-snmp is installed and SNMP notifications are enabled.

References