Forwarded from National Information Sharing and Analysis Center Cybersecurity Information Alert NISAC-200-202609-00000003
[Content Description]
Researchers discovered that Zimbra Collaboration contains an OS Command Injection vulnerability(CVE-2026-73570). When the optional package zimbra-snmp is installed and the SNMP notification function is enabled, unauthenticated remote attackers can execute arbitrary operating system commands with Zimbra user privileges by sending specially crafted SMTP requests. This vulnerability has been exploited by hackers. Please confirm and patch as soon as possible.
[Affected Platforms]
Zimbra Collaboration versions 10.1.20(exclusive) and earlier
[Recommended Measures]
The official source has released a patch for the vulnerability. Please upgrade Zimbra Collaboration to version 10.1.20(inclusive) or later. For detailed information, please refer to the official advisory at the following URL: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-73570
2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570
3. https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories