What is CVE-2026-73570?
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Timeline
- 2026-08-13Published to the U.S. National Vulnerability Database (NVD)
- 2026-08-14NVD record last updated
- 2026-08-21First covered in a defend.network daily briefing
Affected product
See advisory
Remediation Steps
- Apply Zimbra patch for CVE-2026-73570 immediately
- Review and revoke any exposed credentials or authentication tokens
- Implement network segmentation to restrict unauthenticated access to Zimbra services
- Monitor logs for evidence of exploitation or reconnaissance activity
References
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.