Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

CVE-2026-73570: Zimbra RCE via Crafted SMTP When zimbra-snmp Is Installed (Fixed in 10.1.20)

High CVE-2026-73570 — An unauthenticated attacker can run commands on Zimbra Collaboration servers by sending crafted SMTP traffic if the optional SNMP package and notifications are enabled. Exploited in the wild. How to check and fix.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: If your Zimbra Collaboration server (ZCS) has the optional zimbra-snmp package installed with SNMP notifications on, an unauthenticated attacker can send crafted SMTP that ends up as OS commands run as the zimbra user. It's being exploited. Upgrade to ZCS 10.1.20, or remove/disable zimbra-snmp.

CVECVE-2026-73570
ProductZimbra Collaboration Suite (ZCS) before 10.1.20
ConditionOptional zimbra-snmp package installed and SNMP notifications enabled
TypeUnsanitised input in SNMP notification processing → OS command injection
Auth neededNone; the attacker just talks SMTP to your mail server
CVSS 3.18.9 High
Exploited?Yes, CISA KEV 2026-08-21

What the bug is

Zimbra can send SNMP traps when certain mail events happen. The code that builds those notifications didn’t sanitise data that comes from incoming SMTP sessions, so a crafted SMTP conversation results in shell commands running on the server as the zimbra user. Mail servers accept SMTP from anyone on the internet by design, so if the conditions are met, anyone can trigger it.

From the zimbra account an attacker can read every mailbox, steal credentials, and send mail as your domain.

Am I affected?

su - zimbra -c "zmcontrol -v"          # version: below 10.1.20?
rpm -qa | grep zimbra-snmp              # RHEL/Rocky/Oracle
dpkg -l | grep zimbra-snmp              # Ubuntu
su - zimbra -c "zmprov gs $(zmhostname) zimbraSnmpNotify zimbraSmtpNotify"

Vulnerable if the version is below 10.1.20 and zimbra-snmp is installed and SNMP notifications are enabled. Older unsupported releases (8.8.15, 9.0) should be treated as vulnerable and upgraded regardless.

How to patch

  1. Upgrade to ZCS 10.1.20 or later following Zimbra’s upgrade instructions (run the installer as root, then zmcontrol restart).
  2. If you can’t upgrade today and don’t need SNMP monitoring, disable notifications: zmprov ms $(zmhostname) zimbraSnmpNotify FALSE zimbraSmtpNotify FALSE, or uninstall the zimbra-snmp package.

Check for compromise

  • Look for unexpected processes owned by zimbra (shells, curl/wget, crypto miners) and new files in /opt/zimbra/jetty/webapps/, which is where Zimbra web shells usually land.
  • Check the zimbra user’s crontab (crontab -u zimbra -l) and ~zimbra/.ssh/authorized_keys.
  • Review /var/log/zimbra.log and mailbox.log around odd SMTP sessions.
  • If compromised: rebuild, restore mailboxes from backup, and reset every user’s password and the LDAP/MySQL credentials.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories