CISA Warns of Zimbra OS Command Injection Vulnerability Active Exploitation (CVE-2026-73570)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of Zimbra vulnerability, tracked as CVE-2026-73570. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 24, 2026.
The vulnerability exists in the SNMP monitoring component when SNMP notifications are enabled. Successful exploitation of the vulnerability may allow an unauthenticated attacker to send specially crafted SMTP requests, leading to arbitrary code execution.
Zimbra Collaboration Suite is an enterprise-class software platform that provides secure email, calendar, and team communication tools for businesses and organizations. Over 200,000 businesses in 140 countries currently use this email and collaboration platform.
Affected versions
The vulnerability affects Zimbra Collaboration versions prior to 10.1.20.
Mitigation
Users must upgrade to the Zimbra Collaboration version 10.1.20 to patch the vulnerability.
For more information, please refer to the Zimbra Security Advisory.
Qualys Detection
Qualys customers can scan their devices with QIDs 735101 and 532185 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.
References
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/

Comments are closed.