peter bassill · operator
$ cve CVE-2026-73570 JSON

CVE-2026-73570 KEV

8.9
HIGH · CVSS 3.1 · EPSS 11.7% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2026-08-24.

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Scoring

CVSS8.9 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
EPSS11.74% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2026-08-24
Public exploitnone known
Published2026-08-13
Last modified2026-08-24

CISA KEV

NameZimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Added2026-08-21
Due2026-08-24
Vendor / productSynacor / Zimbra Collaboration Suite (ZCS)
Ransomware usenone reported

Affected (1)

VendorProduct
synacorzimbra collaboration suite

References

→ the Explorer  ·  watch your stack  ·  NVD