Threat intel / CVE tracker

CVE-2026-73570

High KEV · actively exploited PoC available
CVSS base score
8.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Vendor
synacor
Product
zimbra collaboration suite
Affected
synacor zimbra collaboration suite
Weakness
CWE-78 · Command injection
Published
Aug 13, 2026
Last modified
Aug 24, 2026
CVSS version
v3.1
Views
3
// References & exploits
NVD record Search PoCs