High 8.9 Actively Exploited

Zimbra RCE exploited in the wild (CVE-2026-73570) [PoC]

CVE-2026-73570

By Yazoul AI · automated

CVE-2026-73570: Unauthenticated RCE in Zimbra Collaboration 10.1.x with SNMP enabled (CVSS 8.9, actively exploited). Update to 10.1.20 immediately.

Affected: Synacor Zimbra Collaboration Suite

Actively exploited in the wild - CVE-2026-73570 is a high-severity remote code execution vulnerability in Zimbra Collaboration (ZCS) before 10.1.20 that grants unauthenticated attackers the ability to execute arbitrary OS commands as the Zimbra user. Patched in version 10.1.20 - update immediately if you run the optional zimbra-snmp package.

Overview

CVE-2026-73570 affects Zimbra Collaboration Suite (ZCS) environments where the optional zimbra-snmp package is installed and SNMP notifications are enabled. The vulnerability stems from improper sanitization of untrusted input during SNMP notification processing.

An unauthenticated attacker can exploit this flaw by sending specially crafted SMTP requests to the target server. When these requests are processed through the vulnerable SNMP notification pathway, they can trigger execution of arbitrary operating system commands under the privileges of the Zimbra user.

This vulnerability carries a CVSS score of 8.9 (High), with a network attack vector. Although the attack complexity is rated as High, no privileges or user interaction are required. The CISA Known Exploited Vulnerabilities (KEV) catalog has confirmed active exploitation in the wild, making immediate patching essential.

The EPSS score of 0.5% indicates a relatively low probability of broad exploitation in the next 30 days, but the confirmed in-the-wild attacks mean your attack surface should not be underestimated.

Impact

Successful exploitation grants an unauthenticated remote attacker the ability to execute arbitrary commands on the mail server as the Zimbra user. This could lead to:

  • Full compromise of the email system, including reading, modifying, or deleting mailboxes
  • Data exfiltration of sensitive communications
  • Lateral movement within your network if the Zimbra server has elevated access
  • Installation of backdoors or web shells for persistent access

Remediation

Zimbra has released version 10.1.20 which addresses this vulnerability. Take the following steps immediately:

  1. Upgrade Zimbra Collaboration to version 10.1.20 or later without delay.
  2. If upgrade is not immediately possible, disable SNMP notifications or uninstall the zimbra-snmp package as a temporary mitigation.
  3. Review Zimbra server logs for suspicious SMTP or SNMP activity that may indicate prior exploitation.
  4. Monitor for compromise indicators - unexpected processes, outbound connections, or modified files in Zimbra directories.

For detailed patching instructions, refer to the official Zimbra security advisory. Stay current with related incident reports at breach reports and follow ongoing coverage at security news.

Security Insight

CVE-2026-73570 highlights a concerning pattern in Zimbra’s security posture - the repeated exploitation of optional components that expand the attack surface. Like past Zimbra vulnerabilities in the “mailsync” and “majordomo” components, the attack surface here is a non-default feature that many administrators may not even realize is active in their deployments. Organizations using Zimbra should audit their installations for seasonal and optional components that are enabled without a clear business need and treat each one as a potential entry point for attackers. The confirmed KEV status also underscores that Zimbra remains a high-value target for threat actors, and rapid patching of these auxiliary components is as critical as patching the core mail server itself.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
HORKimhab/CVE-2026-73570

CVE-2026-73570

★ 5
gabrielunknown/CVE-2026-73570

Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)

★ 4
jishino567/CVE-2026-73570

PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)

★ 2
INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

Wazuh Rules for Detection Zimbra (CVE-2026-73570).

★ 0

Showing 4 of 4 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Other Synacor Zimbra Collaboration Suite Vulnerabilities

View all Synacor Zimbra Collaboration Suite vulnerabilities →

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.