High-Severity Vulnerability in Zimbra Collaboration Suite
21 August 2026
Attackers can exploit a high-severity vulnerability in Zimbra Collaboration Suite to achieve remote code execution. Patch immediately.
Background
Zimbra has released a patch to address a high-severity vulnerability (CVE-2026-73570) affecting Zimbra Collaboration Suite (ZCS). This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 8.9 out of 10.
Impact
Successful exploitation of this command injection vulnerability could allow an unauthenticated attacker to execute arbitrary commands with privileges. The exploitation could enable attackers to gain full control of a targeted Zimbra server, establish persistence, access email accounts, harvest credentials, and move laterally to other systems.
Known Exploitation
This vulnerability is reportedly being actively exploited in the wild.
Affected Products
The vulnerability affects ZCS versions prior to 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
Recommendations
Users and administrators of affected products are advised to update to the latest version immediately.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-73570
https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html
