Code Injection in Zimbra Collaboration Suite (CVE‑2026‑73570) Enables Remote Command Execution on Unpatched Servers
What It Is – CVE‑2026‑73570 is a code‑injection flaw in Zimbra Collaboration Suite (ZCS) that allows an unauthenticated attacker to execute arbitrary OS commands when the optional zimbra‑snmp package is installed and SNMP notifications are enabled.
Exploitability – The vulnerability is publicly disclosed, a patch (ZCS v10.1.20) was released on 20 July 2026, and in‑the‑wild exploitation has been confirmed by the Polish CERT and the Shadowserver Foundation.
Affected Products – Zimbra Collaboration Suite ≤ v10.1.19 with the zimbra‑snmp package installed and SNMP notifications turned on (approximately 8 200 internet‑facing instances, of which at least 274 are known to be compromised).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Controls (CC6.1 & CC7.1): Unpatched software and unnecessary services constitute a control gap that can be cited as a deficiency in System Operations and Change Management.
- Continuous Monitoring: Demonstrating that all third‑party email platforms are patched and that risky services are disabled provides audit‑ready evidence of due diligence.
- Vendor Risk Management: Organizations that rely on Zimbra as a third‑party service must verify the provider’s patch cadence and configuration hardening to satisfy Vendor Management criteria.
Recommended Actions
- Apply the ZCS v10.1.20 patch immediately to every Zimbra instance.
- Disable the optional
zimbra‑snmppackage or turn off SNMP notifications if not required. - Run an automated, continuous vulnerability scan against all mail servers and ingest findings into your SOC 2 evidence repository.
- Map the patch‑management and service‑hardening steps to SOC 2 controls (CC6.1, CC7.1) and retain screenshots or configuration logs as audit evidence.
Source: Help Net Security – Unpatched Zimbra servers are falling to CVE‑2026‑73570 attacks