ZeroHour
Organization

Zimbra

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

CISA added actively exploited Zimbra flaw CVE-2026-73570 (unauthenticated OS command injection RCE) to its KEV catalog, setting an August 24, 2026 federal patch deadline.

CISA added CVE-2026-73570, an unauthenticated OS command injection flaw in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities catalog after CERT Polska confirmed active exploitation. The flaw lets attackers execute shell commands as the zimbra user via the snmp_notify parameter when the SNMP trap service is enabled and the default swatchdog service is running. Zimbra patched the issue in version 10.1.20 released July 20, 2026, 28 days before exploitation was confirmed. Under BOD 22-01, federal civilian agencies must patch by August 24, 2026.

Security Affairs · 24d agoExploit / PoC in the wildCVE-2026-73570

Related CVEs

  • Unauthenticated OS Command Injection RCE in Synacor Zimbra Collaboration Suite
    CVE-2026-73570 is an OS command injection vulnerability (CWE-78) in Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20, caused by improper sanitization of untrusted input during SNMP notification processing. It is triggered when the optional zimbra-snmp package is installed and SNMP notifications are enabled: an unauthenticated attacker sends specially crafted SMTP requests that the flawed notification path turns into execution of arbitrary operating system commands. Successful exploitation runs commands as the Zimbra user, giving attackers control of the mail server's service account with high confidentiality and integrity impact across the host. Only ZCS deployments running the optional SNMP component with notifications enabled are vulnerable; other Zimbra installs are not exposed to this specific flaw. The flaw is under active exploitation: CISA added it to the KEV catalog on 2026-08-21, Poland's CERT has warned of in-the-wild attacks, unpatched Zimbra servers are reported compromised, and two public proof-of-concept exploits exist.
    · Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20 (when the optional zimbra-snmp package is installed and SNMP notifications are enabled) KEV PoC ×4large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.