← Browse

CVE-2026-73570

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
8.9 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
EPSS — probability of exploitation (30 days)
32.4%
98.3th percentile
CISA KEV
Listed
Added 2026-08-21 · patch by 2026-08-24
Weakness / dates
CWE-78
Published 2026-08-13 · modified 2026-08-24

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionNNone
ScopeCChanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityLLow

Timeline

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Affected

synacor

References

Official: NVD · CVE.org