Latest Zimbra vulnerability: CVE-2026-73570 #
Zimbra disclosed that certain versions of Zimbra Collaboration are affected by an unauthenticated remote code execution (RCE) vulnerability if the server is configured with the snmp_notify parameter. A crafted SMTP message sent to the Zimbra server can reach the vulnerable logic of the SNMP notification handler and an attacker can achieve RCE unauthenticated. The vulnerability has been designated CVE-2026-73570 and has been rated high with a CVSS score of 8.9.
There is evidence that CVE-2026-73570 is being actively exploited in the wild and the vulnerability has been added to the CISA KEV list August 21th, 2026.
The following versions are affected
- Zimbra Collaboration: Versions prior to 10.1.20
What is Zimbra? #
Zimbra Collaboration is a collaboration software suite, which provides users with a quickly deployable E-mail and webmail server.
What is the impact? #
Successful exploitation of this vulnerability would allow a remote attacker without authentication to achieve full remote code execution on the host server with the privileges of the Zimbra system.
Are any updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- Zimbra Collaboration: Upgrade to version 10.1.20 or later.
How to find potentially vulnerable systems with runZero #
From the Software Inventory, use the following query to locate potentially impacted assets:
vendor:=Zimbra AND product:=Collaboration AND _asset.protocol:snmp