CVE-2026-73570 โ Zimbra Collaboration Server Command Injection
CVE-2026-73570 is a command-injection vulnerability (CVSS 8.9) in the optional zimbra-snmp package of Zimbra Collaboration Server. CERT Polska warned that the flaw is being actively exploited in the wild in recent breach attempts. With the package installed and SNMP notifications enabled, an unauthenticated attacker can send crafted SMTP/SNMP input that reaches a system shell and executes arbitrary operating-system commands as the Zimbra user. The flaw is patched in version 10.1.20, so every instance still on an earlier build is exposed.
Indicators & Mitigation
| Field | Value |
|---|---|
| CVE | CVE-2026-73570 |
| CVSS | 8.9 (High) |
| Product | Zimbra Collaboration Server (optional zimbra-snmp package) |
| Type | Command injection โ unauthenticated remote code execution |
| Exploitation | Active in the wild (CERT Polska warning) |
| Fixed release | 10.1.20 |
| Indicator check | Inspect /var/log/zimbra.log for Zimbra service restarts; look for executed files under webapps/ and /tmp/ for the last 30 days |
Impact
Zimbra Collaboration Server is widely deployed as an email and collaboration suite, including in the Australian managed-services market. Unpatched internet-facing instances are exposed to unauthenticated remote code execution as the Zimbra user. CERT Polska directs operators to patch internet-facing Zimbra instances immediately.