CVE-2026-73570 – Zimbra Collaboration
CVSS 8.9
IMPORTANT
Zero Day – Immediate Deployment
“Active exploitation turns this mail-server flaw into an immediate compromise risk.”
Zimbra Collaboration before 10.1.20 is affected by a remote code execution vulnerability when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An unauthenticated attacker can send crafted SMTP requests that execute operating system commands as the Zimbra user. The CVSS score is 8.9, which is High severity.
CVE-2026-73570 is confirmed as actively exploited. Zimbra Collaboration 10.1.20 patches the command injection vulnerability in the SNMP monitoring component.
Key Details
- Affected Product
- Synacor Zimbra Collaboration Suite
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-78
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.