## Overview
CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) list on August 21, 2026. This vulnerability affects Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. The addition to the KEV list indicates a federal deadline for remediation due to active exploitation.
## Technical Details
The vulnerability arises from improper sanitization of untrusted input during the processing of SNMP notifications. An unauthenticated attacker can exploit this flaw by sending specially crafted SMTP requests. Successful exploitation leads to the execution of arbitrary operating system commands as the Zimbra user. The CVSS score of 8.9 highlights the severity of this vulnerability, making it critical for organizations using ZCS.
## Impact
If exploited, this vulnerability allows attackers to gain control over the Zimbra server. They can execute commands that may compromise sensitive data or disrupt services. Organizations that rely on ZCS for collaboration and communication are particularly at risk, especially if they have not updated to the latest version.
## Mitigation
Defenders should immediately upgrade to Zimbra Collaboration Suite version 10.1.20 or later. Organizations should also disable the zimbra-snmp package if it is not needed. Regularly review and apply security patches to maintain a secure environment. Monitor network traffic for unusual SMTP requests that may indicate exploitation attempts.
CSURFACE Threat Sensor