Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-73570

Published 2026-08-13
Updated 28 days ago
Vendor/s
Synacor
Product/s
Zimbra Collaboration Suite (ZCS)
Version/s
* > 10.1.20
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
8.9
/ 10
High
Severity Details
Base score
8.9 High
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Description

CVE-2026-73570 is a high-severity RCE vulnerability in Zimbra Collaboration Suite (ZCS) affecting versions prior to 10.1.20. Patch immediately.

CPE

Synacor logo
Synacor
Product Version Start Version End (excl.) Status
zimbra_collaboration_suite * 10.1.20 vulnerable

Related weakness (CWE)

CWE-78

Remediation plan

1

Apply official patches

Immediately download and install the security patches provided by Synacor for Zimbra Collaboration Suite. Ensure the zimbra-snmp package is updated to the latest version to address the improper input sanitization flaw.

2

Update affected systems

Upgrade all Zimbra Collaboration Suite (ZCS) instances to version 10.1.20 or later. This version removes the vulnerability by properly sanitizing untrusted input during SNMP notification processing.

3

Restrict access

If patching cannot be performed immediately, disable the optional zimbra-snmp package or restrict SMTP traffic to known, trusted mail relays. Use firewalls to limit access to management interfaces and SNMP services.

4

Monitor for exploitation

Audit system process logs for unexpected shell activity (e.g., /bin/sh or /bin/bash) initiated by the Zimbra user. Monitor SMTP logs for suspicious payloads or unusual command strings that deviate from standard mail traffic.

Detection Guidance

"Detection should focus on identifying anomalous command execution originating from the Zimbra service. Monitor audit logs for the zimbra-snmp process spawning unexpected child shells. Search SMTP logs for requests containing shell metacharacters like backticks, semicolons, or pipes. Additionally, implement network signatures to detect outbound connections from the Zimbra server to unknown external IPs, which may indicate a successful reverse shell or data exfiltration attempt following exploitation."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management