NCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Zimbra has fixed a vulnerability in Zimbra Collaboration Suite. The vulnerability is located in Zimbra Collaboration Suite, version prior to 10.1.20. Unauthenticated attackers can execute OS commands via specially crafted SMTP requests. This requires that the zimbra-snmp package is installed and SNMP notifications are enabled.
CSIRTS triage
- What
- Unauthenticated attackers can execute OS commands via specially crafted SMTP requests when zimbra-snmp package is installed and SNMP notifications are enabled.
- Who is affected
- Zimbra Collaboration Suite deployments running versions before 10.1.20 with zimbra-snmp package and SNMP notifications enabled.
- Urgency
- High; the vulnerability is actively exploited and allows unauthenticated remote code execution.
- Action
- Upgrade Zimbra Collaboration Suite to version 10.1.20 or later immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Collaboration Suite
Get an email when a new Collaboration Suite advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0324
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-73570Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 61% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-73570 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedZimbra Multiple Vulnerabilitieshkcert
- unknownexploitedZimbra security advisory (AV26-816) – Update 1cccs
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerabilitycisa-kev
- unknownexploitedMultiple vulnerabilities in Synacor Zimbra Collaboration (August 19, 2026)cert-fr-avis
- highCVE-2026-73570: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when…nvd
Recent advisories for Zimbra Collaboration Suite
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalexploitedCVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerabilitycisa-kev · 2026-08-21
- highexploitedRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitecisa · 2026-07-23
- criticalexploitedCVE-2025-48700: Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerabilitycisa-kev · 2026-04-20
- criticalexploitedCVE-2025-66376: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerabilitycisa-kev · 2026-03-18
- criticalexploitedCVE-2020-7796: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerabilitycisa-kev · 2026-02-17
- criticalexploitedCVE-2025-68645: Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerabilitycisa-kev · 2026-01-22
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21
- unknownNCSC-2026-0322 [1.00] [M/H] Vulnerabilities fixed in Splunk Enterprise by Splunk2026-08-21