Emergency Security Bulletin: OS Command Injection in Zimbra Collaboration Suite SNMP Notification Processing

https://www.redlegg.com/hubfs/Theme-2024/overlay-red.png featured image

By: RedLegg's Cyber Threat Intelligence Team

About:

CVE-2026-73570 is a high-severity OS command injection vulnerability affecting the SNMP monitoring component of Zimbra Collaboration Suite when the optional zimbra-snmp package is installed and SNMP notifications are enabled.

The vulnerability results from improper sanitization of untrusted input during SNMP notification processing. An unauthenticated remote attacker can exploit the flaw without credentials or user interaction to execute arbitrary operating system commands with the privileges of the Zimbra user.

Successful exploitation may allow an attacker to compromise the affected Zimbra environment and establish persistence. CVE-2026-73570 is confirmed to be actively exploited in the wild.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.


VULNERABILITIES

OS Command Injection in Zimbra Collaboration Suite SNMP Notification Processing

Identifier: CVE-2026-73570 
PoC or Exploitation: Confirmed actively exploited in the wild.  
CVSS Score: 8.9 (High, CVSS v3.1)

Update / Patch:

Zimbra has released a fixed version addressing this vulnerability.
 
Affected versions include:
Zimbra Collaboration Suite (ZCS), all versions prior to 10.1.20, when the optional zimbra-snmp package is installed and SNMP notifications are enabled
 
Fixed versions include:
Zimbra Collaboration Suite 10.1.20
 
Zimbra Security Advisories:
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories


Description:

CVE-2026-73570 is a command injection vulnerability in the SNMP monitoring component of Zimbra Collaboration Suite, present when SNMP notifications are enabled.
 
Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated remote attacker can trigger execution of arbitrary operating system commands with the privileges of the Zimbra user. This flaw requires no credentials and no user interaction.

 

Mitigation Recommendation:

Apply the fixed version, 10.1.20 or later immediately.
 
Confirm whether the zimbra-snmp package is installed and SNMP notifications are enabled in your environment to determine direct exposure.
 
Review Zimbra logs, including /var/log/zimbra.log, for unexpected Zimbra service restarts or other anomalies that may indicate attempted or successful exploitation.
 
Check for unauthorized files, webshells, or other artifacts on Zimbra servers, since successful exploitation grants command execution as the zimbra user and may enable persistence mechanisms.
 
Restrict network access to the SNMP service to trusted management networks only.