LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 21, 2026
CVSS 8.9 · High⚠ Actively exploited (CISA KEV)
8.9
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 24, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog on Aug 21, 2026, with a federal patch deadline of Aug 24, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

CVE-2026-73570 is an OS command injection weakness in Synacor Zimbra Collaboration Suite (ZCS). An unauthenticated attacker who can reach the mail path may send specially crafted SMTP traffic that causes the product to run operating system commands in the context of the Zimbra user. For organizations that expose Zimbra to the internet or to broad internal mail flows, that combination matters: mail infrastructure is high-value, often trusted by other systems, and command execution on the Zimbra account can lead to further compromise of mail data, configurations, and adjacent hosts. Confirm exact product builds, fixed releases, and deployment notes against the vendor advisory before you act.

CISA’s required action framing emphasizes applying vendor mitigations, aligning with BOD 26-04 risk-based update priorities and forensics triage expectations, evaluating internet exposure, and discontinuing use if mitigations are unavailable. Treat this as a priority inventory and patch problem for any ZCS estate that accepts SMTP from untrusted sources.

How it works

The reported weakness class is CWE-78: OS command injection. In this pattern, application code builds or invokes a shell or OS command using data that an attacker can influence, without sufficient validation or safe APIs. Here, public detail states that specially crafted SMTP requests can reach a code path that results in arbitrary operating system command execution as the Zimbra user. Unauthenticated reachability via SMTP means the attacker does not need a valid mailbox password if they can deliver or present the malicious SMTP interaction to a vulnerable service endpoint.

Do not assume a particular SMTP verb, header, or payload shape beyond what the vendor documents. In general for this class, successful abuse yields process execution under the service account (Zimbra), which may allow reading or altering mail-related files, dropping persistence, pivoting with local credentials or trust relationships, or abusing the host’s network position. Specifics of exploit mechanics, preconditions, and fixed versions must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Zimbra Collaboration Suite typically runs as an on-premises or self-managed collaboration stack providing mail, calendar, and related services—often on Linux hosts with SMTP, web UI, and related daemons. Inventory every system that identifies as ZCS / Zimbra, including MX hosts, internal relays that still run full ZCS, lab/staging clones, and appliances or VMs stood up for migration.

How to remediate

Patch first: apply the vendor-supplied update or mitigation package named in the Synacor/Zimbra advisory for CVE-2026-73570, following their install and restart order. Validate post-update version strings and service health. Align timing and evidence collection with your policy and with CISA BOD 26-04 style prioritization for internet-facing and high-impact assets.

If you can't patch immediately

Reduce attack surface until the vendor fix is installed. Compensating controls do not replace the patch.

If your data may have been exposed

Actively exploited mail-stack vulnerabilities often precede account takeover, message theft, or lateral movement. If you suspect exploitation, isolate affected hosts as appropriate, preserve volatile and log evidence, rotate credentials and API secrets that the Zimbra user or administrators could access, and begin incident response including mailbox and forwarding-rule review. Known ransomware use is not documented in the facts provided for this CVE; still treat confirmed command execution as a full host and identity incident. As a routine hygiene step, individuals can run a free exposure scan of their work email addresses against known breach corpora to see whether those addresses already appear in unrelated dumps while enterprise forensics proceeds.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSynacor · Zimbra Collaboration Suite (ZCS)
WeaknessCWE-78
CVSS base score8.9 (High)
CVSS vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
PublishedAug 13, 2026
Added to CISA KEVAug 21, 2026
Federal patch deadlineAug 24, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities