Critical Remote Code Execution in Zimbra Collaboration Suite (CVE‑2026‑73570) Added to CISA KEV Catalog
What It Is — Zimbra Collaboration Suite (ZCS) contains an OS command‑injection flaw (CVE‑2026‑73570) that lets an unauthenticated attacker execute arbitrary shell commands as the zimbra system user. The defect resides in the SNMP monitoring component when the optional zimbra‑snmp package is installed and the snmp_notify parameter is enabled.
Exploitability — Active exploitation has been confirmed by CERT Polska; the vulnerability is listed in the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog. The flaw received a critical CVSS rating (≈9.8) and a patch (ZCS 10.1.20) was released 28 days before exploitation was observed.
Affected Products — Zimbra Collaboration Suite (any version < 10.1.20) with the SNMP trap service enabled and the swatchdog service running (default on most installations).
Why It Matters for Compliance & Audit Readiness
- Control Mapping – The issue highlights gaps in configuration‑management and change‑control processes; mapping these to SOC 2 CC6.1 (System Configuration) is essential for audit evidence.
- Continuous Evidence Collection – Detecting the exploit relies on log‑review and file‑integrity monitoring; automated evidence feeds satisfy SOC 2 CC7.2 (Monitoring) and provide a defensible audit trail.
- Patch‑Management Discipline – The narrow window between patch release and active exploitation underscores the need for documented, time‑bound patch‑deployment controls (SOC 2 CC6.2).
Recommended Actions
- Verify that the
zimbra‑snmppackage is removed or the SNMP trap service is disabled if not required. - Apply ZCS 10.1.20 (or later) immediately and document the patch‑installation as evidence.
- Review
/var/log/zimbra.logfor the service‑status entries listed by CERT Polska and audit file changes in/opt/zimbra/jetty/webapps/,/opt/zimbra/jetty_base/webapps/, and/tmp/. - Integrate SNMP‑service configuration checks into your continuous compliance monitoring platform to generate real‑time alerts and audit logs.
Source: Security Affairs – CISA adds Zimbra flaw to KEV catalog