- Sources: Zimbra security advisories, CISA KEV catalog
- Summary: CISA added CVE-2026-73570, a Zimbra command injection flaw, to the known exploited vulnerabilities catalog on 2026-08-21 with a remediation due date of 2026-08-24. CISA describes the flaw as reachable by an unauthenticated attacker through crafted SMTP requests. Zimbra's own security advisories page lists the same CVE as a command injection in the SNMP monitoring component, exploitable when SNMP notifications are enabled, with fix release 10.1.20, so the two primary sources disagree on the exposure precondition.
- Why it matters: Unauthenticated command execution as the Zimbra user is listed as exploited in the wild, and the fix is an upgrade to ZCS 10.1.20, so affected builds are those before 10.1.20.
- Follow-up: Resolve whether the entry point is SMTP or the SNMP monitoring component against a Zimbra security advisory.
send feedback on this story