Jump to the main content block

【Vulnerability Alert】Zimbra Collaboration Contains a High-Risk Security Vulnerability (CVE-2026-73570). Please Confirm and Apply Patches as Soon as Possible

publish date : 2026-09-04 update date : 2026-09-04

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026090409090505 Publication Time 2026-09-04 09:07:13
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-04 09:07:13
Impact Level Medium  
[Subject]
【Vulnerability Alert】Zimbra Collaboration Contains a High-Risk Security Vulnerability (CVE-2026-73570). Please Confirm and Apply Patches as Soon as Possible
[Content]

Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202609-00000003

Researchers discovered that Zimbra Collaboration contains an OS Command Injection vulnerability (CVE-2026-73570). When the optional zimbra-snmp package is installed and the SNMP notification function is enabled, an unauthenticated remote attacker may send specially crafted SMTP requests to execute arbitrary operating system commands with Zimbra user privileges. This vulnerability has been exploited by hackers. Please confirm and apply patches as soon as possible.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

Zimbra Collaboration versions prior to 10.1.20

[Recommended Actions]

The official vendor has released a patch for the vulnerability. Please upgrade Zimbra Collaboration to version 10.1.20 or later. For detailed information, please refer to the official advisory. The URL is as follows: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories

[Reference]

1. https://nvd.nist.gov/vuln/detail/CVE-2026-73570
2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570
3. https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: