Loading intelligence…
CVE-2026-73570 is an operating-system command injection issue in Zimbra Collaboration before 10.1.20. The NIST National Vulnerability Database published its record on 2026-08-13 and CISA added the same identifier to the Known Exploited Vulnerabilities catalogue on 2026-08-21.
What happened
Two public vulnerability catalogues carry a record for CVE-2026-73570, an operating-system command injection issue in Zimbra Collaboration. The NIST National Vulnerability Database published its record on 2026-08-13 and now marks it Analyzed. CISA added the same identifier to its Known Exploited Vulnerabilities catalogue on 2026-08-21. This report restates what those two catalogues already publish and adds no non-public detail.
Affected product and versions
Zimbra Collaboration releases before 10.1.20 are recorded as affected. The NVD record notes the issue arises where the optional zimbra-snmp package is installed and SNMP notifications are enabled, so deployments without that package fall outside the recorded affected configuration. CISA lists the same entry under the product name "Zimbra Collaboration Suite (ZCS)" with the vendor project recorded as Synacor.
Severity
The NVD record carries a CVSS v3.1 base score of 8.9, rated HIGH, with the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L. The weakness is classified CWE-78. Both catalogues describe the issue as reachable by an unauthenticated attacker over the network, which is what carries the score despite the high stated attack complexity.
Exploitation status
CISA adds an entry to the Known Exploited Vulnerabilities catalogue only where exploitation has been observed. The entry carries a remediation due date of 2026-08-24 for United States federal civilian agencies under binding operational directive BOD 26-04. CISA records known ransomware campaign use as Unknown — that is the catalogue's own value and should not be read as either the presence or the absence of ransomware activity. ThreatBharat holds no independent telemetry on exploitation of this identifier.
Defensive recommendation
Update Zimbra Collaboration to 10.1.20 or later, following the vendor's published security advisories. Where the update cannot be applied at once, establish whether the optional zimbra-snmp package is installed and whether SNMP notifications are enabled, since the recorded affected configuration depends on both. Treat internet-facing deployments as the priority and retain mail-server logs covering the period since the NVD record was published so that any later investigation has something to read.
Source attribution
CISA Known Exploited Vulnerabilities catalogue and the NIST National Vulnerability Database. ThreatBharat observed the same identifier in both public catalogues. No non-public source informed this report and no organisation is named as affected.
Attributes advertised by the source, alongside what ThreatBharat itself observed. Claimed figures are the seller's, not findings.
Both the CISA Known Exploited Vulnerabilities catalogue and the NIST National Vulnerability Database carry a record for CVE-2026-73570 with the same product and the same weakness classification (CWE-78).
ThreatBharat has not independently reproduced or observed exploitation of this identifier.
Zimbra Collaboration is a mail and collaboration platform commonly deployed on internet-facing infrastructure, so a command-execution issue reachable without authentication in an affected configuration is directly exposed.
Command execution as the service account on an affected deployment, in the configuration the NVD record describes.
No independent ThreatBharat telemetry on exploitation. Neither catalogue names affected organisations, and CISA records known ransomware campaign use as Unknown.
HIGH because two independent public catalogues carry the same identifier with consistent product and weakness detail, and this report restates only what they publish.
Attributed to 2 sources, 2 of them counted as independent corroboration.
2 further sources are counted but not named, because identifying them would disclose where ThreatBharat has access.
Each statement below records what ThreatBharat asserts and what that assertion rests on.
Multi-source corroboration
Observed across 2 independent publishers (NIST NVD — National Vulnerability Database CVE API and CISA — Known Exploited Vulnerabilities catalogue), sharing 21 comparable CVE records. Relative publication ordering cannot be determined from this sample. One publisher's timestamps are day-resolution, so intervals shorter than one day are not distinguishable. Sample: meaningful (21 comparable events, ALL_TIME window, analytics 04b.2.0).
CVE-2026-73570
Published by source
The CISA Known Exploited Vulnerabilities catalogue added CVE-2026-73570 on 2026-08-21, with a remediation due date of 2026-08-24 and known ransomware campaign use recorded as Unknown.
CVE-2026-73570
Vulnerability activity
The NIST National Vulnerability Database records CVE-2026-73570 against Zimbra Collaboration before 10.1.20, weakness CWE-78, with a CVSS v3.1 base score of 8.9 (HIGH).
Update Zimbra Collaboration to 10.1.20 or later in line with the vendor's published security advisories. Where that cannot happen immediately, check whether the optional zimbra-snmp package is present and whether SNMP notifications are enabled, and prioritise internet-facing deployments. Preserve mail-server logs from the publication date onward.
Publication is not confirmation. A report describes a claim that was made. Unless a report says so explicitly, it does not assert that any dataset is authentic or that a named organisation has confirmed a breach. How we publish
© 2026 ThreatBharat. All rights reserved.
An independent platform. Not affiliated with, or endorsed by, the Government of India or any government body.