CISA_KEV · AUGUST 2026 · CONFIRMED

Zimbra Collaboration Suite OS Command Injection Vulnerability

Severity
HIGH
Affected component
zimbra collaboration suite (other)
Affected versions
>= 10.1.16, <= 10.1.16 or >= 10.1.14, <= 10.1.14 or >= 10.1.13, <= 10.1.13 or >= 10.1.10, <= 10.1.10 or >= 10.1.6, <= 10.1.6 or >= 10.1.5, <= 10.1.5 or >= 10.1.4, <= 10.1.4 or >= 10.1.1, <= 10.1.1 or >= 10.1.0, <= 10.1.0 or >= 10.1.0.beta, <= 10.1.0.beta or >= 10.0.0-GA, <= 10.0.0-GA or >= 10.0.0, <= 10.0.0 or >= 9.0.0, <= 9.0.0 or >= 8.8.15, <= 8.8.15 or >= 8.8.12, <= 8.8.12 or >= 8.8.11, <= 8.8.11 or >= 8.8.10, <= 8.8.10 or >= 8.8.9, <= 8.8.9 or >= 8.8.8, <= 8.8.8 or >= 8.7.11, <= 8.7.11 or >= 8.8.7, <= 8.8.7 or >= 8.8.6, <= 8.8.6 or >= 8.8.5, <= 8.8.5 or >= 8.8.4, <= 8.8.4 or >= 8.8.3, <= 8.8.3 or >= 8.8.2, <= 8.8.2 or >= 8.8.0beta2, <= 8.8.0beta2 or >= 8.8.0.beta1, <= 8.8.0.beta1 or >= 8.7.10, <= 8.7.10 or >= 8.7.9, <= 8.7.9 or >= 8.7.7, <= 8.7.7 or >= 8.7.6, <= 8.7.6
Patched version
Not yet available
CVE-2026-73570

Zimbra Collaboration Suite (ZCS) has a confirmed OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands. Users of affected versions should upgrade immediately.

What happened

Zimbra Collaboration Suite (ZCS) versions from 8.7.6 to 10.1.16 and beta versions are affected by an OS command injection vulnerability tracked as CVE-2026-73570. This vulnerability allows unauthenticated attackers to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. The vulnerability was first flagged on August 21, 2026, and confirmed on August 24, 2026. CISA has ordered urgent patching of this flaw, and over 270 Zimbra servers have already been breached in ongoing attacks.

The vulnerability exists due to improper sanitization of untrusted input during SNMP notification processing. When SNMP notifications are enabled on the targeted system, successful exploitation allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If zimbra collaboration suite is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Zimbra Collaboration Suite versions from 8.7.6 to 10.1.16 or any beta versions, you are affected.

What should I do right now?

Upgrade to the latest version of Zimbra Collaboration Suite (version 10.1.20 or later) and monitor for any suspicious activity.

Has this been exploited in the wild?

Yes, this vulnerability has been exploited in the wild. Over 270 Zimbra servers have been breached.

Sources

Join the 0Day waitlist →

← Back to all threats