S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-73570 Scanner

CVE-2026-73570 Scanner - OS Command Injection vulnerability in Zimbra Collaboration Suite

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-73570
8.9
CVSShigh
Exploitable remotely over the internet · no authentication required.

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Collaborationby Zimbra
AFFECTED< 10.1.20SAFE ✓≥ 10.1.20
Updated Sep 11, 2026View on NVD →
Detail

The Zimbra Collaboration Suite is widely utilized in corporations and institutions for efficient email communication and collaboration. It is employed by IT departments to manage organizational communication resources due to its robust features and integration capabilities. The suite is accessible through web-based and desktop client applications, catering to a broad user base. System administrators rely on it for deploying collaborative environments swiftly, providing shared calendars, contacts, and file storage. Its user-friendly interface and flexibility in integrating with third-party extensions make it a favored choice. Furthermore, its open-source nature ensures adaptability and continual development by a community of contributors.

OS Command Injection is a critical security vulnerability that arises when input is improperly sanitized, allowing attackers to execute arbitrary system commands. This flaw is prevalent in applications that incorporate user-controlled data into system-level operations. In the context of Zimbra Collaboration Suite, such vulnerabilities enable the injection of malicious code through manipulated SMTP requests. Exploitations of this nature can lead to severe consequences such as unauthorized commands being executed on the backend servers. The vulnerability is notably dangerous as it allows attackers remote access and control over the affected system, posing significant threats to data integrity and privacy. It has been actively abused, heightening security risks for unpatched systems.

The vulnerability specifically targets the SNMP notification processing in Zimbra Collaboration Suite versions prior to 10.1.20. When SNMP notifications are activated, combined with the zimbra-snmp package, the endpoint is exposed to crafted SMTP requests designed to exploit input sanitization weaknesses. These malicious requests forge log entries that, when processed by the swatchdog service, trigger command execution through unsanitized Perl backtick operations. Attackers can thus leverage these vulnerabilities to inject operating system commands, gaining unauthorized access capabilities. The endpoint's reliance on improperly sanitized input to execute commands makes it a focal point for attack vectors. This makes the suite's SNMP notification process a crucial security concern, necessitating immediate mitigation measures.

Exploiting this vulnerability can have serious implications, including the execution of remote code as the zimbra user. Successful exploitation allows attackers to deploy webshells within the server directories, facilitating subsequent unauthorized actions. This includes stealing email credentials, accessing the entire mailbox contents on the compromised server, and moving laterally to manipulate internal network resources. The vulnerability poses a significant risk to organizational data security, potentially leading to data breaches and reputation damage. Users may experience unauthorized data access, deletion, or alteration, compromising both personal and enterprise-level information confidentiality. Such infiltration can further pave the way for more extensive network attacks, amplifying organizational vulnerabilities.

REFERENCES

Solution Advice
  • Upgrade Zimbra Collaboration Suite to version 10.1.20 or later to patch the OS command injection vulnerability.
  • As a temporary measure, disable SNMP notifications by unsetting the zimbraSnmpNotifyTrap configuration to reduce the risk until an upgrade is possible.
  • Remove or uninstall the zimbra-snmp package and stop the swatchdog service to limit the attack vectors available to potential attackers.
  • Conduct a security audit of the system to identify any unauthorized script deployments or additional vulnerabilities.
  • Monitor server logs regularly to detect any unusual activity or unauthorized access attempts that may indicate exploitation efforts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-73570 Scanner - OS Command Injection vulnerability in Zimbra Collaboration Suite | S4E