DIRAS TAKE
Urgent — CISA placed this flaw on its Known Exploited Vulnerabilities list with a short remediation window, so prioritize applying Synacor’s update or temporary mitigations on exposed Zimbra servers now.
What is CVE-2026-73570?
An unauthenticated remote attacker can send malformed SMTP traffic to Zimbra Collaboration Suite and, when the optional zimbra-snmp component is present with SNMP notifications turned on, abuse how those notifications are processed to execute operating-system commands as the Zimbra user. CVE-2026-73570 impacts ZCS 10.x releases prior to 10.1.20. Successful exploitation requires network reachability to the affected SMTP service and the zimbra-snmp/SNMP-notifications configuration; no valid account or user interaction is necessary. The weakness is classified as CWE-78 (OS Command Injection).
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Which versions of Synacor Zimbra Collaboration Suite (ZCS) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 10.x | before 10.1.20 | 10.1.20 |
Is CVE-2026-73570 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-08-21, and U.S. federal agencies were required to address it by 2026-08-24.
How to fix CVE-2026-73570
- Upgrade Zimbra Collaboration Suite 10.x to 10.1.20.
- If immediate upgrade is not possible, disable or remove the zimbra-snmp package or turn off SNMP notifications.
- Limit network access to the Zimbra SMTP service to trusted hosts and networks.
- Review logs and system activity for signs of unexpected command execution or suspicious SMTP traffic.
Frequently asked questions
Is CVE-2026-73570 being actively exploited?
CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog on 2026-08-21, requiring remediation by 2026-08-24 for federal agencies.
Which Zimbra Collaboration Suite versions are affected by CVE-2026-73570?
Zimbra Collaboration Suite 10.x releases before 10.1.20 are affected.
Is there a patch for CVE-2026-73570?
Yes. Synacor released a fix in ZCS version 10.1.20.
Does CVE-2026-73570 require authentication?
No. The issue can be triggered without credentials when zimbra-snmp is installed and SNMP notifications are enabled.
References
- nvd.nist.gov/vuln/detail/CVE-2026-73570
- cve.org/CVERecord?id=CVE-2026-73570
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570
- wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- wiki.zimbra.com/wiki/Security_Center
- All Synacor CVEs on CVE Radar
- CVEs published in September 2026