Sploitus

CVE-2026-73570

2 known exploits for CVE-2026-73570

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Affected products
Zimbra Collaboration
Synacor Zimbra Collaboration Suite
< 10.1.20
CVSS 3.1
8.9 HIGH
EPSS
0.5% (43th percentile)
Weakness
CWE-78
NVD status
Analyzed
Published
2026-08-13
CVE-2026-73570 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-73570

Proof-of-concept code and exploit modules indexed by Sploitus