Remote Code Execution in Zimbra Collaboration through Improper Input Sanitization
CVE-2026-73570
Key Information:
- Vendor
Zimbra
- Status
- Vendor
- CVE Published:
- 13 August 2026
Badges
What is CVE-2026-73570?
CVE-2026-73570 is a critical remote code execution vulnerability found in Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20, particularly when the optional zimbra-snmp package is installed and SNMP notifications are active. Zimbra is an open-source collaboration platform used by various organizations for email and calendar functionalities. The vulnerability arises from improper sanitization of untrusted input during the processing of SNMP notifications, enabling unauthenticated attackers to dispatch specially crafted SMTP requests. This could allow these attackers to execute arbitrary commands on the underlying operating system as the Zimbra user, severely compromising the security and integrity of the affected systems.
Potential impact of CVE-2026-73570
-
Remote Code Execution: The vulnerability can be exploited to execute arbitrary operating system commands, granting attackers significant control over the server. This risk can lead to full system compromise, allowing attackers to manipulate data, install malware, or orchestrate further attacks within the network.
-
Data Breaches: Unauthorized command execution may facilitate data breaches, where sensitive organizational and personal information accessed through Zimbra can be exfiltrated. Such breaches can lead to regulatory penalties, loss of reputation, and financial harm due to compromised client trust.
-
Service Disruption: Exploitation of this vulnerability may result in service interruptions, impacting business operations that rely on the Zimbra platform. This disruption can lead to downtime, loss of productivity, and financial repercussions as services become unavailable to users.
CISA has reported CVE-2026-73570
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-73570 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Collaboration 0 < 10.1.20
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570
4 days ago
Exploited RCE Flaws and Infrastructure Attacks Define this Cybersecurity Week in August 2026 | eSecurity Planet
Weekly summary of Cybersecurity Insider newsletters for August 2026.
6 days ago
274 Zimbra Servers Compromised, 8,200 Unpatched
Attackers exploited CVE-2026-73570 to compromise 274 Zimbra servers, while 8,200 systems remain unpatched. Learn what administrators should check.
1 week ago
References
EPSS Score
20% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 💰
Used in Ransomware
- 🟡
Public PoC available
- 📈
Vulnerability started trending
- 🦅
CISA Reported
- 👾
Exploit known to exist
- 📰
First article discovered by Securityweek
Vulnerability published
Vulnerability Reserved
