High CVE-2026-73570 — An unauthenticated attacker can run commands on Zimbra Collaboration servers by sending crafted SMTP traffic if the optional SNMP package and notifications are enabled. Exploited in the wild. How to check and fix.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: If your Zimbra Collaboration server (ZCS) has the optional zimbra-snmp package installed with SNMP notifications on, an unauthenticated attacker can send crafted SMTP that ends up as OS commands run as the zimbra user. It's being exploited. Upgrade to ZCS 10.1.20, or remove/disable zimbra-snmp.
| CVE | CVE-2026-73570 |
|---|---|
| Product | Zimbra Collaboration Suite (ZCS) before 10.1.20 |
| Condition | Optional zimbra-snmp package installed and SNMP notifications enabled |
| Type | Unsanitised input in SNMP notification processing → OS command injection |
| Auth needed | None; the attacker just talks SMTP to your mail server |
| CVSS 3.1 | 8.9 High |
| Exploited? | Yes, CISA KEV 2026-08-21 |
Zimbra can send SNMP traps when certain mail events happen. The code that builds those notifications didn’t sanitise data that comes from incoming SMTP sessions, so a crafted SMTP conversation results in shell commands running on the server as the zimbra user. Mail servers accept SMTP from anyone on the internet by design, so if the conditions are met, anyone can trigger it.
From the zimbra account an attacker can read every mailbox, steal credentials, and send mail as your domain.
su - zimbra -c "zmcontrol -v" # version: below 10.1.20?
rpm -qa | grep zimbra-snmp # RHEL/Rocky/Oracle
dpkg -l | grep zimbra-snmp # Ubuntu
su - zimbra -c "zmprov gs $(zmhostname) zimbraSnmpNotify zimbraSmtpNotify"
Vulnerable if the version is below 10.1.20 and zimbra-snmp is installed and SNMP notifications are enabled. Older unsupported releases (8.8.15, 9.0) should be treated as vulnerable and upgraded regardless.
zmcontrol restart).zmprov ms $(zmhostname) zimbraSnmpNotify FALSE zimbraSmtpNotify FALSE, or uninstall the zimbra-snmp package.zimbra (shells, curl/wget, crypto miners) and new files in /opt/zimbra/jetty/webapps/, which is where Zimbra web shells usually land.crontab -u zimbra -l) and ~zimbra/.ssh/authorized_keys./var/log/zimbra.log and mailbox.log around odd SMTP sessions.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.