---
id: CVE-2026-73570
title: >-
  A remote code execution vulnerability exists in Zimbra Collaboration (ZCS)
  before 10.1.20 when the optional zimbra-snmp package is installed and SNMP
  notifications are enabled
summary: >-
  A remote code execution vulnerability exists in Zimbra Collaboration (ZCS)
  before 10.1.20 when the optional zimbra-snmp package is installed and SNMP
  notifications are enabled. Due to improper sanitization of untrusted input
  during SNMP …
severity: high
cvss: 8.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L'
cwe:
  - CWE-78
vendor: synacor
product: zimbra_collaboration_suite
affected:
  - zimbra_collaboration_suite < 10.1.20
patched:
  - zimbra_collaboration_suite 10.1.20
published: '2026-08-13'
updated: '2026-08-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73570'
references:
  - url: 'https://wiki.zimbra.com/wiki/Security_Center'
    label: cve@mitre.org
  - url: 'https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories'
    label: cve@mitre.org
  - url: >-
      https://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.11736
epssPercentile: 0.95922
kev: true
kevDateAdded: '2026-08-21'
kevDueDate: '2026-08-24'
kevRansomware: false
exploited: true
ingestedAt: '2026-08-22T13:32:36.086Z'
exploits:
  github: 8
  githubRepos:
    - 'https://github.com/HORKimhab/CVE-2026-73570'
    - 'https://github.com/gabrielunknown/CVE-2026-73570'
    - 'https://github.com/jishino567/CVE-2026-73570'
  nuclei:
    - network/cves/2026/CVE-2026-73570
  checkedAt: '2026-09-25T08:21:11.864Z'
exploitAvailable: true
---

## Overview

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

## Affected

- `zimbra_collaboration_suite < 10.1.20`

## Remediation

Upgrade past the affected range:

- `zimbra_collaboration_suite 10.1.20`
