Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

🚨SEVERITY: HIGH — CVSS 8.9Security Advisory

TL;DR 📌

  • A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as…
  • Highest CVSS: 8.9 (High).
  • Listed in CISA KEV (2026-08-21) — this is being exploited in the wild.
  • Fixed in 10.1.20 — upgrade to this release or later.
  • CVEs: CVE-2026-73570.

What it is

CVE-2026-73570 is an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS), affecting versions before 10.1.20. It only applies where the optional zimbra-snmp package is installed and SNMP notifications are enabled.

The flaw lies in how ZCS processes SNMP notifications: untrusted input isn’t properly sanitised before being passed through to the operating system. An attacker doesn’t need any credentials or prior access — they send specially crafted SMTP requests to the server, and the malformed input reaches the SNMP notification handling path, resulting in arbitrary OS command execution as the Zimbra user.

This is a network-reachable, unauthenticated attack path via SMTP, with no user interaction required. The CVSS vector confirms this: attack complexity is high, but no privileges and no user interaction are needed. The confidentiality and integrity impact is rated high, with availability impact rated low — consistent with command execution as the Zimbra service account rather than full system compromise.

CVE-2026-73570 is listed in the CISA Known Exploited Vulnerabilities catalogue, added on 2026-08-21.

What to do

  • Upgrade Zimbra Collaboration Suite to 10.1.20 or later. This is the fixed version listed by NVD.
  • If you cannot patch immediately, check whether the zimbra-snmp package is installed and whether SNMP notifications are enabled — this vulnerability only applies where both conditions hold. Disabling SNMP notifications or removing the package removes the exposure.
  • Given this is listed in CISA KEV, treat patching as urgent rather than routine — this indicates known exploitation.
  • Review SMTP-facing logs for anomalous or malformed traffic around the time SNMP notification processing would have handled it, particularly on any Zimbra instance with zimbra-snmp installed prior to patching.
  • Confirm the version in use against 10.1.20 directly rather than relying on package metadata alone, given command execution runs as the Zimbra user and could otherwise go unnoticed.

For leadership 🧭

Executive summary. Zimbra Collaboration Suite servers with the optional SNMP notification package enabled can be commanded to run operating system commands by anyone able to reach them over SMTP, with no login required. This is already listed in CISA’s Known Exploited Vulnerabilities catalogue, so any unpatched instance with zimbra-snmp installed should be treated as an active risk, not a backlog item.

Why it matters:

  • The attack path is unauthenticated SMTP traffic to the Zimbra server — no credentials, no prior foothold, and no user interaction needed to trigger command execution.
  • Exploitation results in arbitrary OS commands running as the Zimbra service account, giving high confidentiality and integrity impact on mail data and configuration.
  • Exposure is conditional but common: only instances with the optional zimbra-snmp package installed and SNMP notifications enabled are affected, so many Zimbra deployments may already be exposed without realising it.
  • CISA added this to its Known Exploited Vulnerabilities catalogue on 2026-08-21, indicating it is known to be exploited in the wild.

Now / Next / Later:

  • Now: Check every Zimbra Collaboration Suite instance for the zimbra-snmp package and whether SNMP notifications are enabled; if either is true and you’re below 10.1.20, disable SNMP notifications or remove the package immediately as a stopgap.
  • Next: Schedule and apply the upgrade to ZCS 10.1.20 or later on all affected servers, confirming the installed version directly rather than trusting package metadata.
  • Later: Review whether the zimbra-snmp package needs to be installed at all in your environment, and build version verification for optional Zimbra components into routine patch audits so SNMP notification exposure doesn’t go unnoticed again.

Source