Zimbra Collaboration Suite OS Command Injection Vulnerability
- Severity
- HIGH
- Affected component
- zimbra collaboration suite (other)
- Affected versions
- >= 10.1.16, <= 10.1.16 or >= 10.1.14, <= 10.1.14 or >= 10.1.13, <= 10.1.13 or >= 10.1.10, <= 10.1.10 or >= 10.1.6, <= 10.1.6 or >= 10.1.5, <= 10.1.5 or >= 10.1.4, <= 10.1.4 or >= 10.1.1, <= 10.1.1 or >= 10.1.0, <= 10.1.0 or >= 10.1.0.beta, <= 10.1.0.beta or >= 10.0.0-GA, <= 10.0.0-GA or >= 10.0.0, <= 10.0.0 or >= 9.0.0, <= 9.0.0 or >= 8.8.15, <= 8.8.15 or >= 8.8.12, <= 8.8.12 or >= 8.8.11, <= 8.8.11 or >= 8.8.10, <= 8.8.10 or >= 8.8.9, <= 8.8.9 or >= 8.8.8, <= 8.8.8 or >= 8.7.11, <= 8.7.11 or >= 8.8.7, <= 8.8.7 or >= 8.8.6, <= 8.8.6 or >= 8.8.5, <= 8.8.5 or >= 8.8.4, <= 8.8.4 or >= 8.8.3, <= 8.8.3 or >= 8.8.2, <= 8.8.2 or >= 8.8.0beta2, <= 8.8.0beta2 or >= 8.8.0.beta1, <= 8.8.0.beta1 or >= 8.7.10, <= 8.7.10 or >= 8.7.9, <= 8.7.9 or >= 8.7.7, <= 8.7.7 or >= 8.7.6, <= 8.7.6
- Patched version
- Not yet available
Zimbra Collaboration Suite (ZCS) has a confirmed OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands. Users of affected versions should upgrade immediately.
What happened
Zimbra Collaboration Suite (ZCS) versions from 8.7.6 to 10.1.16 and beta versions are affected by an OS command injection vulnerability tracked as CVE-2026-73570. This vulnerability allows unauthenticated attackers to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. The vulnerability was first flagged on August 21, 2026, and confirmed on August 24, 2026. CISA has ordered urgent patching of this flaw, and over 270 Zimbra servers have already been breached in ongoing attacks.
The vulnerability exists due to improper sanitization of untrusted input during SNMP notification processing. When SNMP notifications are enabled on the targeted system, successful exploitation allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component.
What to do about it
- Upgrade to the latest version of Zimbra Collaboration Suite (version 10.1.20 or later).
- Disable SNMP notifications if they are not required for your environment.
- Monitor logs for any suspicious activity related to this vulnerability.
- Consult the primary sources for the most up-to-date information and patches.
How 0Day would have caught this
zimbra collaboration suite is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Zimbra Collaboration Suite versions from 8.7.6 to 10.1.16 or any beta versions, you are affected.
What should I do right now?
Upgrade to the latest version of Zimbra Collaboration Suite (version 10.1.20 or later) and monitor for any suspicious activity.
Has this been exploited in the wild?
Yes, this vulnerability has been exploited in the wild. Over 270 Zimbra servers have been breached.
Sources
- NCSC-2026-0324 [1.00] [M/H] Kwetsbaarheid verholpen in Zimbra Collaboration Suite
- CISA orders urgent patching of actively exploited Zimbra flaw
- Hackers breached over 270 Zimbra servers in ongoing attacks
- [CISA KEV] CVE-2026-73570 — Synacor Zimbra Collaboration Suite (ZCS)
- Exploited Zimbra Flaw Highlights Shrinking Window to Patch