HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Remote Code Execution in Zimbra Collaboration Suite (CVE‑2026‑73570) Added to CISA KEV Catalog

CVE‑2026‑73570, an unauthenticated OS command‑injection flaw in Zimbra Collaboration Suite, is being actively exploited and has been placed in the U.S. CISA Known Exploited Vulnerabilities catalog. The issue underscores the need for rigorous configuration‑management and continuous monitoring to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 22, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Remote Code Execution in Zimbra Collaboration Suite (CVE‑2026‑73570) Added to CISA KEV Catalog

What It Is — Zimbra Collaboration Suite (ZCS) contains an OS command‑injection flaw (CVE‑2026‑73570) that lets an unauthenticated attacker execute arbitrary shell commands as the zimbra system user. The defect resides in the SNMP monitoring component when the optional zimbra‑snmp package is installed and the snmp_notify parameter is enabled.

Exploitability — Active exploitation has been confirmed by CERT Polska; the vulnerability is listed in the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog. The flaw received a critical CVSS rating (≈9.8) and a patch (ZCS 10.1.20) was released 28 days before exploitation was observed.

Affected Products — Zimbra Collaboration Suite (any version < 10.1.20) with the SNMP trap service enabled and the swatchdog service running (default on most installations).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – The issue highlights gaps in configuration‑management and change‑control processes; mapping these to SOC 2 CC6.1 (System Configuration) is essential for audit evidence.
  • Continuous Evidence Collection – Detecting the exploit relies on log‑review and file‑integrity monitoring; automated evidence feeds satisfy SOC 2 CC7.2 (Monitoring) and provide a defensible audit trail.
  • Patch‑Management Discipline – The narrow window between patch release and active exploitation underscores the need for documented, time‑bound patch‑deployment controls (SOC 2 CC6.2).

Recommended Actions

  • Verify that the zimbra‑snmp package is removed or the SNMP trap service is disabled if not required.
  • Apply ZCS 10.1.20 (or later) immediately and document the patch‑installation as evidence.
  • Review /var/log/zimbra.log for the service‑status entries listed by CERT Polska and audit file changes in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
  • Integrate SNMP‑service configuration checks into your continuous compliance monitoring platform to generate real‑time alerts and audit logs.

Source: Security Affairs – CISA adds Zimbra flaw to KEV catalog

📰 Original Source
https://securityaffairs.com/197693/security/u-s-cisa-adds-zimbra-collaboration-suite-zcs-flaw-to-its-known-exploited-vulnerabilities-catalog.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →