Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026090409090505 | Publication Time | 2026-09-04 09:07:13 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-04 09:07:13 |
| Impact Level | Medium | ||
| [Subject] 【Vulnerability Alert】Zimbra Collaboration Contains a High-Risk Security Vulnerability (CVE-2026-73570). Please Confirm and Apply Patches as Soon as Possible |
|||
| [Content]
Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202609-00000003 Researchers discovered that Zimbra Collaboration contains an OS Command Injection vulnerability (CVE-2026-73570). When the optional zimbra-snmp package is installed and the SNMP notification function is enabled, an unauthenticated remote attacker may send specially crafted SMTP requests to execute arbitrary operating system commands with Zimbra user privileges. This vulnerability has been exploited by hackers. Please confirm and apply patches as soon as possible. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
Zimbra Collaboration versions prior to 10.1.20 |
|||
|
[Recommended Actions] The official vendor has released a patch for the vulnerability. Please upgrade Zimbra Collaboration to version 10.1.20 or later. For detailed information, please refer to the official advisory. The URL is as follows: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories |
|||
|
[Reference] 1. https://nvd.nist.gov/vuln/detail/CVE-2026-73570 |
|||