
CVE-2026-73570: Zimbra Collaboration Suite — Remote Code Execution Risk (June 2026)
CVE-2026-73570 — Zimbra Collaboration Suite
CVE-2026-73570 is a critical vulnerability in Zimbra Collaboration Suite that allows unauthenticated remote code execution via command injection. The flaw is under active exploitation, confirmed by CERT Polska and added to CISA's Known Exploited Vulnerabilities catalog. No CVSS score is published, but exploitation is ongoing and remediation is urgent.
Attack Vector
Attackers exploit the vulnerability by sending crafted SNMP trap notifications to Zimbra servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The swatchdog service, which runs by default in affected configurations, processes these notifications and is vulnerable to command injection. An unauthenticated attacker can execute arbitrary shell commands as the zimbra user, leading to full compromise of the application and potential lateral movement.
Who Is at Risk
All organizations running Zimbra Collaboration Suite with the zimbra-snmp package installed and SNMP notifications enabled are at risk. The vulnerability affects default deployments where swatchdog is running. Impacted environments are global, with no restriction by sector or geography. Zimbra Collaboration Suite users should assume exposure if SNMP features are enabled.
Patch & Mitigate
- Patch: Apply the latest Zimbra security updates addressing CVE-2026-73570 as soon as possible. Check Zimbra advisories for the exact fixed version and patch deadline.
- Workaround: If immediate patching is not possible, disable the zimbra-snmp package and stop the swatchdog service to mitigate risk.
- Detect: Monitor logs for unusual SNMP trap activity, unexpected commands executed by the zimbra user, and any anomalous process launches associated with swatchdog.
MITRE ATT&CK
- TA0007 — Discovery: Attackers may use this flaw to enumerate system information after gaining code execution.
- T1059 — Command and Scripting Interpreter: Exploitation enables arbitrary shell command execution via command injection.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

