CVE-2026-73570Active Exploitation(synacor / zimbra_collaboration_suite)

CRITICALCVSS 8.9 · HIGHCISA KEV

Exploitation observed; activity peaked at 24 mentions and remains active

Immediate actions

  • Patch synacor zimbra_collaboration_suite systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-24. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zimbra_collaboration_suite

Threat summary

  • Active exploitation appears in 119 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 153 mentions across 22 observed days

What's happening

  • Active exploitation reported across 119 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 72 signals
  • Technical details provided in 106 signals
  • Disclosure: 12 classified signals
  • Peaked 14d ago at 24 mentions (2026-08-25); latest day: 1
  • 153 total mentions across 22 days

Affected systems

Vendors
Products
zimbra_collaboration_suite

Deep dive

Activity timeline153 mentions / 22d
06121824Mentions · 2026-08-13: 2Mentions · 2026-08-19: 2Mentions · 2026-08-20: 21Mentions · 2026-08-21: 17Mentions · 2026-08-22: 17Mentions · 2026-08-23: 6Mentions · 2026-08-24: 19Mentions · 2026-08-25: 24Mentions · 2026-08-26: 13Mentions · 2026-08-27: 5Mentions · 2026-08-28: 9Mentions · 2026-08-29: 2Mentions · 2026-08-30: 4Mentions · 2026-08-31: 2Mentions · 2026-09-01: 2Mentions · 2026-09-03: 1Mentions · 2026-09-04: 1Mentions · 2026-09-08: 1Mentions · 2026-09-09: 1Mentions · 2026-09-11: 1Mentions · 2026-09-18: 2Mentions · 2026-09-27: 1PoC Mentioned / Linked · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-22: 2PoC Mentioned / Linked · 2026-08-23: 2PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-26: 3PoC Mentioned / Linked · 2026-08-28: 1PoC Mentioned / Linked · 2026-08-31: 1PoC Mentioned / Linked · 2026-09-04: 1Exploit Tool / Code · 2026-08-22: 1Exploit Tool / Code · 2026-08-23: 1Exploit Tool / Code · 2026-08-25: 1Exploit Tool / Code · 2026-08-26: 2Exploit Tool / Code · 2026-09-18: 1Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-08-20: 21Active Exploitation · 2026-08-21: 12Active Exploitation · 2026-08-22: 13Active Exploitation · 2026-08-23: 3Active Exploitation · 2026-08-24: 17Active Exploitation · 2026-08-25: 20Active Exploitation · 2026-08-26: 8Active Exploitation · 2026-08-27: 5Active Exploitation · 2026-08-28: 8Active Exploitation · 2026-08-30: 3Active Exploitation · 2026-08-31: 2Active Exploitation · 2026-09-01: 1Active Exploitation · 2026-09-03: 1Active Exploitation · 2026-09-04: 1Active Exploitation · 2026-09-08: 1Active Exploitation · 2026-09-18: 2Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-20: 11Patch / Workaround · 2026-08-21: 8Patch / Workaround · 2026-08-22: 8Patch / Workaround · 2026-08-23: 3Patch / Workaround · 2026-08-24: 8Patch / Workaround · 2026-08-25: 11Patch / Workaround · 2026-08-26: 7Patch / Workaround · 2026-08-27: 2Patch / Workaround · 2026-08-28: 6Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-08-30: 3Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-03: 1Patch / Workaround · 2026-09-08: 1Technical Details · 2026-08-13: 2Technical Details · 2026-08-19: 2Technical Details · 2026-08-20: 15Technical Details · 2026-08-21: 15Technical Details · 2026-08-22: 14Technical Details · 2026-08-23: 4Technical Details · 2026-08-24: 10Technical Details · 2026-08-25: 14Technical Details · 2026-08-26: 9Technical Details · 2026-08-27: 4Technical Details · 2026-08-28: 7Technical Details · 2026-08-29: 1Technical Details · 2026-08-30: 3Technical Details · 2026-08-31: 2Technical Details · 2026-09-04: 1Technical Details · 2026-09-08: 1Technical Details · 2026-09-18: 208-1308-2008-2208-2408-2608-2808-3009-0109-0409-0909-1809-27
Signal classification6 categories
Active Exploitation
11877.6%
Disclosure
127.9%
Patch
95.9%
General
85.3%
PoC
42.6%
Exploit
10.7%
Referenced assets99 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-132
Disclosure2
2026-08-192
Active Exploitation1Disclosure1
2026-08-2021
Active Exploitation20Patch1
2026-08-2117
Active Exploitation12Disclosure3General1Patch1
2026-08-2217
Active Exploitation13Disclosure1Patch2PoC1
2026-08-236
Active Exploitation3Disclosure1Patch1PoC1
2026-08-2419
Active Exploitation17Disclosure1General1
2026-08-2524
Active Exploitation20Exploit1General1Patch2
2026-08-2613
Active Exploitation8Disclosure2General1PoC2
2026-08-275
Active Exploitation5
2026-08-289
Active Exploitation8Disclosure1
2026-08-292
General1Patch1
2026-08-304
Active Exploitation3Patch1
2026-08-312
Active Exploitation2
2026-09-012
Active Exploitation1General1
2026-09-031
Active Exploitation1
2026-09-041
Active Exploitation1
2026-09-081
Active Exploitation1
2026-09-091
General1
2026-09-111
General1
2026-09-182
Active Exploitation2
Full discourse20 posts
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    CVE-2026-73570 is exploited in the wild. This unauthenticated RCE hits Zimbra Collaboration via SNMP notifications. Patch to 10.1.20 now. #Zimbra #CVE #RCE #RemoteCodeExecution #ExploitedInTheWild #InfoSec #PatchNow https://securityonline.info/zimbra-cve-2026-73570/

    Post summary

    CVE-2026-73570 is a publicly exploited, unauthenticated RCE in Zimbra, mitigated by patch 10.1.20.

    026093374.9K
    13.0K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Attackers are exploiting a Zimbra flaw that can lead to unauthenticated RCE. CVE-2026-73570 affects ZCS before 10.1.20 when zimbra-snmp is installed and SNMP notifications are enabled. Crafted SMTP requests may execute OS commands as the Zimbra user. What to check: https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html

    Post summary

    Zimbra's SNMP flaw (CVE-2026-73570) is currently being actively exploited to achieve unauthenticated remote code execution through crafted SMTP requests.

    3171821927.3K
    2.4M followersView on X
  • Giuseppe `N3mes1s`@N3mes1s
    PoC

    CVE-2026-73570: Zimbra Collaboration unauthenticated RCE via Swatchdog/SNMP log-injection command injection swatchrc dosnmp Perl backtick https://www.pruva.dev/reproductions/REPRO-2026-00327 #pruva

    Post summary

    The announcement presents CVE‑2026‑73570 with a proof‑of‑concept available online, detailing an unauthenticated remote code execution via command injection in Zimbra Collaboration.

    014040232.8K
    13.5K followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2026-73570 (CVSS 8.9): Unauthenticated command injection in Zimbra Collaboration (ZCS) SNMP notification processing allows attackers to execute arbitrary OS commands as the zimbra user via crafted SMTP requests. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJ6aW1icmEt6YKu5Lu257O757ufIg== 🎯494.3K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="zimbra-邮件系统" 🔖Refer: https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post confirms that attackers are actively exploiting CVE‑2026‑73570, a command‑injection flaw in Zimbra SNMP notification processing, with no mention of patches or PoC code.

    013034153.5K
    14.8K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added Zimbra Collaboration Suite OS command injection vulnerability CVE-2026-73570 to our Known Exploited Vulnerabilities Catalog. Visit http://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/LR6MNUqBjh

    Post summary

    Zimbra Collaboration Suite's OS command injection vulnerability CVE-2026-73570 is identified as actively exploited, and mitigations are advised.

    11113649.7K
    302.8K followersView on X
  • Netlas.io@Netlas_io
    Active Exploitation

    CVE-2026-73570: Unauthenticated RCE in Zimbra, 8.9 rating ‍🔥 A Zimbra vulnerability disclosed last week is now being actively exploited in the wild. It allows an unauthenticated attacker to execute arbitrary OS commands as the zimbra user via specially crafted requests. Successful exploitation requires the optional Zimbra-snmp package and enabled SNMP notifications. 👉 https://nt.ls/RfXS9

    Post summary

    The post reports that CVE‑2026‑73570, an unauthenticated RCE in Zimbra, is actively exploited in the wild and provides technical details about the attack vector.

    09020141.6K
    7.7K followersView on X
  • Ratan Jyoti@reach2ratan
    Active Exploitation

    🚨 **Threat in the Wild: Zimbra CVE-2026-73570** This is one I wouldn't leave for the next patching cycle. More than **270 Zimbra servers have reportedly already been compromised** through an actively exploited command-injection vulnerability. What makes it concerning is the attack path. No stolen password. No phishing click. A specially crafted SMTP request can lead to OS command execution on vulnerable Zimbra installations where the optional `zimbra-snmp` package and SNMP notifications are enabled. If you run Zimbra, I would check this today: → Upgrade to **ZCS 10.1.20 or later** → Check whether `zimbra-snmp` and SNMP notifications are enabled → Hunt for unexpected Zimbra service restarts → Look for files created by the `zimbra` user in: `/opt/zimbra/jetty/webapps/` `/opt/zimbra/jetty_base/webapps/` `/tmp/` → Review suspicious SMTP activity and outbound connections → If the server was exposed and vulnerable, don't just patch — **assume possible compromise and hunt** CISA has already added this vulnerability to its KEV catalogue. The lesson is simple: **When exploitation is already happening in the wild, patching closes the door. Threat hunting tells you whether someone entered before you closed it.** Tagging a few researchers whose security work I follow: @GossiTheDog @cyb3rops @MalwareTechBlog @_JohnHammond #Zimbra #CVE202673570 #ThreatIntel #CyberSecurity #ThreatHunting #DFIR #SOC #CISO

    Post summary

    CVE-2026-73570 is actively exploited in the wild, with over 270 compromised Zimbra servers; patching to ZCS 10.1.20 or later and proactive threat hunting are recommended.

    0140213936
    26.9K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🚨 CISA Warns of Actively Exploited Zimbra RCE Vulnerability CISA has added CVE-2026-73570, a high-severity remote code execution vulnerability affecting Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. * CVE: CVE-2026-73570 * Product: Zimbra Collaboration Suite (ZCS) * Severity: HIGH * CVSS: 8.9 * Vulnerability: OS Command Injection / Remote Code Execution * CWE: CWE-78 * Authentication Required: None * User Interaction Required: None * CISA Status: ACTIVELY EXPLOITED The vulnerability affects Zimbra Collaboration versions prior to 10.1.20 when: * The optional zimbra-snmp package is installed * SNMP notifications are enabled An unauthenticated remote attacker can send specially crafted SMTP requests that exploit insufficient sanitization during SNMP notification processing. Successful exploitation may allow arbitrary operating-system commands to execute with the privileges of the Zimbra user. ⚠️ CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog on August 21, 2026. * CISA's SSVC assessment identifies exploitation as "active" * Technical impact is classified as "total" * The KEV remediation due date is August 24, 2026 ⚠️ Analyst Note: The exploitation path makes this vulnerability especially concerning for exposed mail infrastructure. It does NOT require authentication or user interaction, although the CVSS vector rates attack complexity as HIGH. Importantly, not every Zimbra installation is vulnerable. The affected configuration requires the optional zimbra-snmp package to be installed with SNMP notifications enabled. Organizations operating Zimbra should urgently identify affected installations and upgrade to ZCS 10.1.20 or later in accordance with vendor guidance. Given confirmed exploitation, defenders should also consider affected systems potentially exposed prior to remediation and perform appropriate forensic triage rather than treating patching alone as sufficient. Official Sources: NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-73570 CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570 Zimbra Security Advisories: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories #DDW #Zimbra #CVE #CISA #CyberSecurity #Vulnerability #ThreatIntelligence

    Post summary

    CISA confirms that CVE-2026-73570, a high‑severity RCE in Zimbra, is actively exploited in the wild, and urges an immediate upgrade to version 10.1.20 or newer.

    0402387.0K
    205.0K followersView on X
  • CERT@certlv
    Active Exploitation

    ‼️Brīdinājums! Konstatēta Zimbra Collaboration Suite (ZCS) augstas bīstamības ievainojamības (CVE-2026-73570) aktīva izmantošana kiberuzbrukumos. Vairāk: https://www.cert.lv/lv/2026/09/zimbra-collaboration-suite-ievainojamibas-aktiva-izmantosana-uzbrukumos https://t.co/5Gvzqx5LgX

    Post summary

    The post warns of active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite, but offers no technical details, PoC, or patch information.

    0801742.5K
    5.7K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Active Exploitation

    🛑 Zimbra Plus de 270 serveurs de messagerie compromis grâce à la faille CVE-2026-73570. Une alerte à prendre au sérieux liée à cette faille permettant l'injection de commande au niveau de l'OS. Plus d'infos : - https://www.it-connect.fr/zimbra-cve-2026-73570-serveurs-compromis/ #infosec #zimbra https://t.co/UqbgLj19j2

    Post summary

    CVE‑2026‑73570 is a proven OS‑level command injection flaw in Zimbra, actively exploited with more than 270 servers compromised, yet no PoC or official patch is mentioned.

    01301421.6K
    11.7K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Zimbra ZCS SNMP Notification RCE (CVE-2026-73570) için PoC exploit bugün yayınlandı. Zimbra kullanan sunucu sahiplerinin mutlaka güncelleme yapması gerekiyor.

    Post summary

    A proof‑of‑concept exploit for Zimbra ZCS SNMP Notification RCE (CVE-2026-73570) was released today, and users are urged to apply the available update.

    0501482.3K
    2.4K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    Alert! Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22. Top: US (41 IPs). Detection in collaboration with @CERT_Polska_en Public Dashboard: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=compromised_website&source=compromised_website6&tag=zimbra-compromised%2B&data_set=count&scale=log&auto_update=on https://t.co/xieaNhRvSo

    Post summary

    The alert reports widespread active exploitation of CVE‑2026‑73570 on Zimbra servers, with over 270 compromised instances identified through scanning.

    1521363.8K
    22.0K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-73570 Vendor: Zimbra Product: Collaboration Description: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. Link: https://github.com/gabrielunknown/cve-2026-73570 #dbugs_vuln

    Post summary

    A PoC/exploit for CVE-2026-73570—a remote code execution vulnerability in Zimbra Collaboration caused by improper SNMP sanitization—has been published, but no active exploitation or patch information is provided.

    0401461.9K
    3.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-73570 - high 🚨 Zimbra Collaboration Suite < 10.1.20 - OS Command Injection > Zimbra Collaboration Suite (ZCS) before version 10.1.20 is vulnerable to OS command i... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-73570 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet discloses a new OS command injection vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite versions below 10.1.20 and provides a link to a Project Discovery library entry.

    0101371.1K
    1.3K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    🚨 Zimbra'da kritik RCE açığı aktif olarak istismar ediliyor! Zimbra Collaboration Suite'te (ZCS) tespit edilen CVE-2026-73570 (CVSS 8.9) güvenlik açığının saldırganlar tarafından aktif olarak istismar edildiği bildirildi. Açık, zimbra-snmp paketi kurulu ve SNMP bildirimleri etkin olan 10.1.20 öncesi Zimbra sürümlerini etkiliyor. Yetersiz input sanitization nedeniyle saldırganlar, özel hazırlanmış SMTP istekleri göndererek kimlik doğrulaması olmadan komut enjeksiyonu gerçekleştirebilir ve Zimbra kullanıcısı yetkileriyle uzaktan işletim sistemi komutları çalıştırabilir. 🔴 Zimbra 10.1.20 ile bu açık kapatıldı. CERT Polska, saldırı belirtisi açısından özellikle şu konumların kontrol edilmesini öneriyor: /var/log/zimbra.log /opt/zimbra/jetty/webapps/ /opt/zimbra/jetty_base/webapps/ /tmp/ Zimbra kullanan sistem yöneticilerinin sürümlerini ve zimbra-snmp yapılandırmasını kontrol etmesi, ayrıca son döneme ait log ve dosya değişikliklerini incelemesi öneriliyor. Not: Açığın aktif olarak istismar edildiğinin bildirilmesi nedeniyle, konu yalnızca güncelleme yapılması gereken bir CVE olarak değerlendirilmemeli; olası kompromizasyon belirtileri de araştırılmalı.

    Post summary

    CVE-2026-73570 is an actively exploited RCE in older Zimbra Collaboration Suite releases; a patch is available in version 10.1.20 and monitoring of logs and snmp configurations is advised.

    1211344.8K
    2.4K followersView on X
  • chum1ng0/security research@chum1ng0
    General

    La Agencia Nacional de Ciberseguridad (ANCI) comparte información sobre el CVE-2026-73570 Zimbra. #Chile #ciberseguridad #ANCI

    Post summary

    The National Cybersecurity Agency announces awareness of CVE-2026-73570 impacting Zimbra, but provides no additional details or context.

    1101332.4K
    9.4K followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    ⚠️ Hackers Breach 270+ Zimbra Servers Through CVE-2026-73570 https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/ More than 270 Zimbra servers have already been compromised in attacks exploiting CVE-2026-73570. The flaw allows unauthenticated remote code execution when SNMP notifications are enabled. At least 8,200 Zimbra instances also remain unpatched, although not all are necessarily exploitable because the vulnerable setup is not enabled by default. Zimbra patched the issue on July 20 with the release of ZCS 10.1.20. #ThreatIntel #Zimbra #CyberSecurity

    Post summary

    Over 270 Zimbra servers have been compromised by CVE‑2026‑73570, illustrating active exploitation of an unauthenticated RCE flaw, while Zimbra released a patch on July 20.

    0301221.4K
    7.2K followersView on X
  •  快乐永远 @syeerzy
    Active Exploitation

    听说今天有很多人被 CVE-2026-73570 漏洞搞了 如果你是 Zimbra Collaboration Suite 用户, 赶快查查你的邮件服务器吧

    Post summary

    The text reports that many users are being affected by CVE-2026-73570 (Zimbra Collaboration Suite), suggesting active in-the-wild exploitation, but provides no technical details, PoC, or patch information.

    1400201.3K
    12.0K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/21追加) #vulnerability 🛡CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability ✅概要 ・深刻度:重要 8.9 (CVSS Base) / MITRE (CNA) ・種別:OSコマンド・インジェクション (CWE-78) ・CVSS:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L Zimbra Collaboration Suite (ZCS) 10.1.20 未満に存在する、SNMP通知処理におけるOSコマンド・インジェクションの脆弱性です。 オプションの zimbra-snmp パッケージがインストールされ、SNMP通知が有効な環境では、未認証のリモート攻撃者が細工したSMTPリクエストを送信することで、Zimbraユーザーの権限で任意のOSコマンドを実行できる可能性があります。 ZCS 10.1.20 で修正されています。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は困難 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月24日 ・BOD 26-04 対処期限(露出なし):2026年9月4日 ✅攻撃前提条件 ・Zimbra Collaboration Suite 10.1.20 未満を使用している ・オプションの zimbra-snmp パッケージがインストールされている ・SNMP通知が有効になっている ・SNMP通知を処理する swatchdog サービスが稼働している ・攻撃者が対象サーバーへSMTPリクエストを送信できる ・攻撃者は認証情報やユーザー操作を必要としない ✅悪用時影響 ・Zimbraユーザーの権限で任意のOSコマンドを実行される可能性がある ・Zimbraがアクセス可能な情報を取得される可能性がある ・Zimbraがアクセス可能なデータを改ざんされる可能性がある ・サービスの可用性に影響が生じる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(CERT Polska) ・概要:CERT Polska は、CVE-2026-73570 が実際の攻撃で悪用されていることを確認し、公表しています。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-73570 ・https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ・https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20 ・https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/ ・https://github.com/cisagov/vulnrichment/blob/develop/2026/73xxx/CVE-2026-73570.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570 ・https://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/ ・https://www.ipa.go.jp/security/vuln/websecurity/os-command.html ・https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk CISA Alert ・https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    The post confirms active exploitation of CVE‑2026‑73570 by CERT Polska, details the OS command injection vulnerability, and notes a patch is available.

    0011227.9K
    44.3K followersView on X
  • YogSotho@YogSoth0
    Exploit

    CVE-2026-73570 - Zimbra SNMP notify exploit ```bash snmptrap -v 2c -c public localhost ZIMBRA-MIB::alert && echo x: Service status change: localhost $(id) changed from stopped to running ``` Literally just this. No magic. Blame swatchdog component #zimbra #exploit #cve #0days #cybersecurity #antisec #brokensec #snmp

    Post summary

    The post presents a minimal yet functional exploit script for CVE‑2026‑73570, illustrating how the Zimbra SNMP notify flaw can be triggered, but does not mention active exploitation or mitigations.

    010101869
    2.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsynacorzimbra_collaboration_suite---

Explore more