Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5490 articles · 195389 vulns · 37/41 feeds (7d)
← Back to list
8.9
CVE-2026-73570KEVEXPLOITEDPATCHED
Zimbra · Collaboration

CVE-2026-73570: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Affected Products

VendorProductVersions
ZimbraCollaboration0

References

  • https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
  • https://wiki.zimbra.com/wiki/Security_Center

Related News (5 articles)

Tier D
SecurityWeek1h ago
Hackers Target Zimbra Servers in Active Exploitation Campaign
→ No new info (linked only)
Tier D
The Hacker News3h ago
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
→ No new info (linked only)
Tier D
BleepingComputer6h ago
Critical Zimbra RCE flaw now actively exploited in attacks
→ No new info (linked only)
Tier B
CERT-FR1d ago
Multiples vulnérabilités dans Synacor Zimbra Collaboration (19 août 2026)
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-73570 | Zimbra Collaboration up to 10.1.19 Notification code injection
→ No new info (linked only)
CVSS 3.18.9 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
10.1.20
CWECWE-78
PublishedAug 13, 2026
Last enriched7d ago
Trending Score124🔥
Source articles5
Independent5
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

LOWCVE-2026-73574
CVE-2026-73574: In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Clie
Trending: 12
MEDIUMCVE-2026-73576
CVE-2026-73576: In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice i
Trending: 8
MEDIUMCVE-2026-73572
CVE-2026-73572: In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Cla
Trending: 8
LOWCVE-2026-73575
CVE-2026-73575: In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange W
Trending: 7
LOWCVE-2026-73571
CVE-2026-73571: An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 13, 2026
Added to CISA KEV
Aug 13, 2026
Discovered by ZDM
Aug 13, 2026
Actively Exploited
Aug 14, 2026
Patch Available
Aug 14, 2026