PT-2026-71676 · Zimbra · Zimbra Collaboration
CVE-2026-73570
·
Published
2026-08-13
·
Updated
2026-09-09
CVSS v3.1
8.9
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration Suite versions prior to 10.1.20
Description
An OS command injection flaw exists in the SNMP monitoring functionality of the Zimbra Collaboration Suite. The issue occurs when the optional
zimbra-snmp package is installed, SNMP notifications are enabled, and the swatchdog service is running. An unauthenticated remote attacker can send specially crafted SMTP requests containing malicious input in the RCPT TO command. Because the system fails to properly sanitize this input before passing it to a shell script used for generating SNMP notifications, the attacker can execute arbitrary operating system commands with the privileges of the zimbra user.Real-world exploitation has been confirmed, with at least 274 servers compromised and over 8,000 unpatched instances identified. Attackers have used this flaw to deploy coin-miner malware and establish persistence via cron jobs and JSP webshells in directories such as
/opt/zimbra/jetty/webapps/, /opt/zimbra/jetty base/webapps/, and /tmp/.Recommendations
Update Zimbra Collaboration Suite to version 10.1.20 or later.
As a temporary mitigation, disable SNMP notifications, stop the
swatchdog service, or remove the zimbra-snmp package.
Restrict SMTP connections to minimize the attack surface until the update is applied.Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zimbra Collaboration