Posting Date: 2026/09/04
【Vulnerability Alert】High-Risk Security Vulnerability in Zimbra Collaboration (CVE-2026-73570), Please Verify and Patch Immediately
- Subject: 【Vulnerability Alert】High-Risk Security Vulnerability in Zimbra Collaboration (CVE-2026-73570), Please Verify and Patch Immediately
- Description:
- Forwarded Security Alert from National Information Security Sharing and Analysis Center (NISAC) Alert ID: NISAC-200-202609-00000003
- Researchers have discovered an OS Command Injection vulnerability (CVE-2026-73570) in Zimbra Collaboration. When the optional package `zimbra-snmp` is installed and SNMP notifications are enabled, an unauthenticated remote attacker can execute arbitrary OS commands with Zimbra user privileges by sending a specially crafted SMTP request. This vulnerability is actively being exploited, so please verify and apply patches as soon as possible.
- Affected Systems:
- Zimbra Collaboration versions prior to (excluding) 10.1.20
- Recommendations:
- The vendor has released a security patch for this vulnerability. Please upgrade Zimbra Collaboration to version 10.1.20 or later. For detailed information, please refer to the official announcement at: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- References:
Computer and Communication Center
Network System Division