/Vulnerability Library

Zimbra Collaboration Suite < 10.1.20 - OS Command Injection

CVE-2026-73570
Verified

Description

Zimbra Collaboration Suite (ZCS) before version 10.1.20 is vulnerable to OS command injection in the SNMP notification processing due to improper input sanitization. According to the NVD, when SNMP notifications are enabled and the zimbra-snmp package is installed, an unauthenticated attacker can inject arbitrary commands using crafted SMTP requests that result in malicious log entries. The swatchdog service monitors the log, and upon matching a pattern, passes the log content to zmsnmptrapd, which unsafely uses the Perl backtick operator to execute commands. This can ultimately allow remote attackers to execute arbitrary operating system commands as the zimbra user. Active exploitation of this vulnerability has been observed in the wild, as confirmed by CERT Polska and CISA.

Severity

High

CVSS Score

8.9

Exploit Probability

12%

Affected Product

zimbra_collaboration_suite

Published Date

August 25, 2026

Template Author

0x_akoko, ritikchaddha

CVE-2026-73570.yaml
8.9Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
CVE ID:
cve-2026-73570
CWE ID:
cwe-78

References

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisorieshttps://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570https://github.com/HORKimhab/CVE-2026-73570https://nvd.nist.gov/vuln/detail/CVE-2026-73570

Remediation Steps

Upgrade Zimbra Collaboration Suite to version 10.1.20 or later. The only complete fix is the 10.1.20 release (July 20, 2026). As a temporary mitigation, disable SNMP notifications (unset zimbraSnmpNotifyTrap) or uninstall the zimbra-snmp package and stop the swatchdog service.