PT-2026-71676 · Zimbra · Zimbra Collaboration

CVE-2026-73570

·

Published

2026-08-13

·

Updated

2026-09-09

CVSS v3.1

8.9

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration Suite versions prior to 10.1.20
Description An OS command injection flaw exists in the SNMP monitoring functionality of the Zimbra Collaboration Suite. The issue occurs when the optional zimbra-snmp package is installed, SNMP notifications are enabled, and the swatchdog service is running. An unauthenticated remote attacker can send specially crafted SMTP requests containing malicious input in the RCPT TO command. Because the system fails to properly sanitize this input before passing it to a shell script used for generating SNMP notifications, the attacker can execute arbitrary operating system commands with the privileges of the zimbra user.
Real-world exploitation has been confirmed, with at least 274 servers compromised and over 8,000 unpatched instances identified. Attackers have used this flaw to deploy coin-miner malware and establish persistence via cron jobs and JSP webshells in directories such as /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty base/webapps/, and /tmp/.
Recommendations Update Zimbra Collaboration Suite to version 10.1.20 or later. As a temporary mitigation, disable SNMP notifications, stop the swatchdog service, or remove the zimbra-snmp package. Restrict SMTP connections to minimize the attack surface until the update is applied.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12669
CVE-2026-73570

Affected Products

Zimbra Collaboration