CVE-2026-73570 KEV
8.9
HIGH · CVSS 3.1 · EPSS 11.7% (pctl 96)
Patch first
On CISA KEV — known exploited in the wild, due 2026-08-24.
Description
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Scoring
| CVSS | 8.9 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
| EPSS | 11.74% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2026-08-24 |
| Public exploit | none known |
| Published | 2026-08-13 |
| Last modified | 2026-08-24 |
CISA KEV
| Name | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability |
|---|---|
| Added | 2026-08-21 |
| Due | 2026-08-24 |
| Vendor / product | Synacor / Zimbra Collaboration Suite (ZCS) |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| synacor | zimbra collaboration suite |
References
→ the Explorer · watch your stack · NVD