Critical Remote Code Execution Vulnerability in Zimbra Collaboration Exploited

Critical Remote Code Execution Vulnerability in Zimbra Collaboration Exploited

First seen 19 Aug 2026, 22:48 UTC Ccb.Belgium.Bemoje.cert.plcvefeed.io 88% similarity 72.9

Article Content

Browse articles
ThreatCluster

A remote code execution vulnerability, CVE-2026-73570, has been identified in Zimbra Collaboration versions prior to 10.1.20. This vulnerability arises from improper sanitization of untrusted input during SNMP notification processing, allowing unauthenticated attackers to execute arbitrary commands as the Zimbra user. Security researchers have reported ongoing exploitation of this vulnerability, which poses significant risks to the confidentiality, integrity, and availability of affected systems. The Centre for Cybersecurity Belgium has issued an urgent advisory recommending immediate patching of vulnerable installations. Organizations are also advised to enhance monitoring and detection capabilities to identify suspicious activities. The vulnerability has a CVSS score of 8.9, indicating a high severity level. Affected systems include those with the optional zimbra-snmp package installed and SNMP notifications enabled. Patching is essential to mitigate risks associated with this vulnerability.

Key Points: • CVE-2026-73570 is a high-severity remote code execution vulnerability in Zimbra. • Exploitation allows unauthenticated attackers to execute arbitrary commands as the Zimbra user. • Immediate patching is recommended due to ongoing exploitation campaigns.

ThreatCluster AI How this analysis works

Timeline

2026-08-13
CVE-2026-73570 published
A remote code execution vulnerability in Zimbra Collaboration was disclosed, affecting versions prior to 10.1.20.
cvefeed.io
2026-08-19
Active exploitation reported
Security researchers confirmed ongoing exploitation of CVE-2026-73570, urging immediate action.
Ccb.Belgium.Be
2026-08-19
Urgent patch recommendation issued
The Centre for Cybersecurity Belgium advised organizations to patch vulnerable systems immediately.
Ccb.Belgium.Be

Community

Browse all →

Tracked Entities in This Story