- Sources: Zimbra patch release post, CISA KEV feed, CISA KEV catalog
- Summary: The CISA catalog entry for CVE-2026-73570 cites Zimbra's own patch release post in its notes field. That post is dated 2026-07-20, describes the flaw as a command injection in the SNMP monitoring component reachable when SNMP notifications are enabled, and calls 10.1.20 the permanent fix for the vulnerability disclosed in Zimbra's 2026-06-26 advisory. Affected builds are those before 10.1.20. CISA still describes the flaw as reachable through crafted SMTP requests, and neither source reconciles that difference. The remediation due date for federal agencies is 2026-08-24. The catalog is at version 2026.08.21 with no addition after this entry.
- Why it matters: The exposed population is any Zimbra build before 10.1.20, and the vendor names SNMP notifications as the precondition while CISA names crafted SMTP requests, so operators who cannot patch today have no single reliable mitigation to fall back on.
- Follow-up: Track whether any source reconciles the SMTP and SNMP descriptions of the same CVE.
send feedback on this story