CVE-2026-73570 – Zimbra Collaboration

CVSS 8.9 IMPORTANT Zero Day – Immediate Deployment

“Active exploitation turns this mail-server flaw into an immediate compromise risk.”

Zimbra Collaboration before 10.1.20 is affected by a remote code execution vulnerability when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An unauthenticated attacker can send crafted SMTP requests that execute operating system commands as the Zimbra user. The CVSS score is 8.9, which is High severity.

CVE-2026-73570 is confirmed as actively exploited. Zimbra Collaboration 10.1.20 patches the command injection vulnerability in the SNMP monitoring component.

Key Details

Affected Product
Synacor Zimbra Collaboration Suite
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-78
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.