Zimbra RCE exploited in the wild (CVE-2026-73570) [PoC]
CVE-2026-73570
CVE-2026-73570: Unauthenticated RCE in Zimbra Collaboration 10.1.x with SNMP enabled (CVSS 8.9, actively exploited). Update to 10.1.20 immediately.
Actively exploited in the wild - CVE-2026-73570 is a high-severity remote code execution vulnerability in Zimbra Collaboration (ZCS) before 10.1.20 that grants unauthenticated attackers the ability to execute arbitrary OS commands as the Zimbra user. Patched in version 10.1.20 - update immediately if you run the optional zimbra-snmp package.
Overview
CVE-2026-73570 affects Zimbra Collaboration Suite (ZCS) environments where the optional zimbra-snmp package is installed and SNMP notifications are enabled. The vulnerability stems from improper sanitization of untrusted input during SNMP notification processing.
An unauthenticated attacker can exploit this flaw by sending specially crafted SMTP requests to the target server. When these requests are processed through the vulnerable SNMP notification pathway, they can trigger execution of arbitrary operating system commands under the privileges of the Zimbra user.
This vulnerability carries a CVSS score of 8.9 (High), with a network attack vector. Although the attack complexity is rated as High, no privileges or user interaction are required. The CISA Known Exploited Vulnerabilities (KEV) catalog has confirmed active exploitation in the wild, making immediate patching essential.
The EPSS score of 0.5% indicates a relatively low probability of broad exploitation in the next 30 days, but the confirmed in-the-wild attacks mean your attack surface should not be underestimated.
Impact
Successful exploitation grants an unauthenticated remote attacker the ability to execute arbitrary commands on the mail server as the Zimbra user. This could lead to:
- Full compromise of the email system, including reading, modifying, or deleting mailboxes
- Data exfiltration of sensitive communications
- Lateral movement within your network if the Zimbra server has elevated access
- Installation of backdoors or web shells for persistent access
Remediation
Zimbra has released version 10.1.20 which addresses this vulnerability. Take the following steps immediately:
- Upgrade Zimbra Collaboration to version 10.1.20 or later without delay.
- If upgrade is not immediately possible, disable SNMP notifications or uninstall the
zimbra-snmppackage as a temporary mitigation. - Review Zimbra server logs for suspicious SMTP or SNMP activity that may indicate prior exploitation.
- Monitor for compromise indicators - unexpected processes, outbound connections, or modified files in Zimbra directories.
For detailed patching instructions, refer to the official Zimbra security advisory. Stay current with related incident reports at breach reports and follow ongoing coverage at security news.
Security Insight
CVE-2026-73570 highlights a concerning pattern in Zimbra’s security posture - the repeated exploitation of optional components that expand the attack surface. Like past Zimbra vulnerabilities in the “mailsync” and “majordomo” components, the attack surface here is a non-default feature that many administrators may not even realize is active in their deployments. Organizations using Zimbra should audit their installations for seasonal and optional components that are enabled without a clear business need and treat each one as a potential entry point for attackers. The confirmed KEV status also underscores that Zimbra remains a high-value target for threat actors, and rapid patching of these auxiliary components is as critical as patching the core mail server itself.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| HORKimhab/CVE-2026-73570 CVE-2026-73570 | ★ 5 |
| gabrielunknown/CVE-2026-73570 Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc) | ★ 4 |
| jishino567/CVE-2026-73570 PoC for CVE-2026-73570 (Zimbra SMTP Command Injection) | ★ 2 |
| INFOKOM-KI/Zimbra-CVE-2026-73570-Rules Wazuh Rules for Detection Zimbra (CVE-2026-73570). | ★ 0 |
Showing 4 of 4 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaSc...
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which...
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability tha...
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to...