Knox CVE Database
/
CVE-2026-73570
High
8.9

CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Added to the CISA KEV catalog:
August 21, 2026

Overview

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Vulnerability details

Affected vendor
Synacor
Affected product
Zimbra Collaboration Suite (ZCS)
Weakness type (CWE)
CWE-78

CVE-2026-73570 is an OS command injection flaw (CWE-78) in Zimbra Collaboration Suite affecting versions before 10.1.20. When the optional zimbra-snmp package is installed and SNMP notifications are active via the snmp_notify parameter, the swatchdog service processes data derived from inbound SMTP traffic. Because that data passes to OS-level command execution without proper sanitization, attacker-controlled input can carry shell metacharacters that the host executes directly. The flaw is network-reachable and requires no authentication, though exploitation depends on the SNMP package being present and notifications being enabled.


An attacker sends specially crafted SMTP requests containing OS command injection payloads. Those payloads propagate through the SNMP notification processing path and are executed by the swatchdog component as the Zimbra OS user. Successful exploitation yields arbitrary command execution under that account, giving the attacker the ability to write files, deploy webshells under the Zimbra web application directories, and pursue further system compromise. CERT Polska has reported active exploitation of this vulnerability in the wild.

Severity and impact

8.9
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
Low

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review /var/log/zimbra.log for entries matching the pattern 'Service status change: <unexpected string> changed from stopped to running' or the corresponding 'running to stopped' entry, which CERT Polska identifies as an indicator of payload execution via the swatchdog component.
  • Audit files created by the zimbra OS user within the past 30 days under /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ — files in those paths not associated with a known upgrade or deployment event warrant immediate investigation.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 24, 2026

Additional hardening

  • Upgrade Zimbra Collaboration Suite to version 10.1.20 or later; this release contains the permanent fix for the SNMP command injection vulnerability disclosed in the June 2026 security advisory.
  • If immediate upgrade is not possible, disable SNMP notifications by setting the snmp_notify parameter to disabled and stop the swatchdog service to remove the vulnerable processing path entirely.
  • Remove or uninstall the zimbra-snmp package on any host where SNMP monitoring is not operationally required, eliminating the attack surface without waiting for a maintenance window.
  • Restrict inbound SMTP access at the network perimeter to known sending sources where architecturally feasible, reducing the pool of hosts that can deliver crafted payloads to the vulnerable component.

Key dates

Published (NVD)
August 13, 2026
Added to CISA KEV
August 21, 2026
Remediation deadline
August 24, 2026
Last updated
August 24, 2026

References

Frequently asked questions

Does CVE-2026-73570 affect my FedRAMP authorization?

If Synacor Zimbra Collaboration Suite (ZCS) runs inside your authorization boundary, CVE-2026-73570 is a direct concern. CISA lists this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 24, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it as a compliance gap.

How does Knox help me handle CVE-2026-73570?

Knox does not patch Synacor Zimbra Collaboration Suite (ZCS) on your behalf. Under the FedRAMP shared responsibility model, that remediation is yours to execute. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. That means exposure surfaces during routine monitoring rather than only when an assessor flags it at review time. For a KEV like CVE-2026-73570, that difference in timing matters: earlier visibility gives you more runway to remediate before a deadline becomes a finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-73570 isn't remediated by August 24, 2026?

Missing the August 24, 2026 deadline turns CVE-2026-73570 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization clean and preserves the agency relationship that depends on it.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting