Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-73570

Zimbra ZCS SNMP Command Injection — Unauthenticated RCE

CVE-2026-73570 — CVSS 8.9 command injection in Zimbra Collaboration Suite's SNMP handler enables unauthenticated remote code execution. Actively exploited in the wild. Patch: Zimbra 10.1.20.

cat cve-2026-73570.json
Vendor
Synacor
Product
Zimbra Collaboration Suite (ZCS)
CVSS
8.9
EPSS (exploit probability)
0.5%
Status
exploited-in-wild
Published

Command injection in Zimbra Collaboration Suite’s SNMP handler. Unauthenticated on affected configurations — no credentials required to reach the vulnerable code path. A remote attacker can send a crafted SNMP request to trigger arbitrary command execution on the ZCS mail server host.

Affected versions: Zimbra Collaboration (ZCS) prior to 10.1.20.

Patch: Released with Zimbra 10.1.20 (July 2026). Active exploitation confirmed by Poland’s CERT Polska in August 2026. Organizations running versions prior to 10.1.20 should treat this as urgent.

If immediate patching is not possible, restrict SNMP access (ports 161/UDP, 162/UDP) to trusted management hosts at the network perimeter. Firewall restriction reduces exposure but does not replace patching.

See Zimbra SNMP RCE Now Exploited in the Wild for full coverage including indicators of compromise references and response steps.