CVE-2026-73570 is a code injection vulnerability in Zimbra Collaboration Suite (ZCS), fixed by the vendor in version 10.1.20. The vulnerability affects mail servers with the optional package "zimbra-snmp" installed and SNMP notifications enabled.
A flaw in the input validation when processing SNMP notifications allows an attacker to execute arbitrary commands on the server with the privileges of the zimbra user, without prior authentication, using specially crafted SMTP requests. The vulnerability is assigned a CVSS score of 8.9.
The National CERT recommendations are:
Update Zimbra Collaboration to version 10.1.20 or later.
If SNMP monitoring is not required, remove the package "zimbra-snmp" or disable SNMP notifications.
Users of versions that are no longer supported by the vendor are recommended to upgrade to a supported version, as patches for these versions are not available.
Limit the exposure of administrative interfaces to the Internet.
In case of suspected compromise, save a forensic copy of the system and logs before any remediation and notify the National CERT.
More details about the vulnerability: https://nvd.nist.gov/vuln/detail/cve-2026-73570