Critical Remote‑Code Execution in Zimbra Collaboration Suite (CVE‑2026‑73570) Exposes Thousands of Mail Servers
What It Is
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20 contain an OS‑command injection flaw in its SMTP handling path. An unauthenticated attacker can embed malicious input in SMTP requests that reaches the Simple Network Management Protocol (SNMP) workflow, triggering arbitrary OS commands executed as the Zimbra service account.
Exploitability
The vulnerability carries an 8.9 CVSS 3.1 score and is confirmed to be actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive on Friday, and ShadowServer has documented dozens of compromised instances across Europe and the United States. No public PoC is required for exploitation—the attack works via crafted SMTP traffic.
Affected Products
All Zimbra Collaboration Suite deployments running versions < 10.1.20 are vulnerable. The issue is most prevalent on internet‑facing mail servers that have the optional zimbra‑snmp package, snmp_notify setting, or swatchdog service enabled.
Why It Matters for Compliance & Audit Readiness
Vendor‑Management & Patch‑Management Controls – SOC 2 CC6.1 (System Operations) and CC7.2 (Change Management) require documented evidence that critical software patches are applied in a timely manner. The continued exposure of > 8,000 instances demonstrates a gap in continuous control monitoring and a lack of defensible audit trails for patch‑status verification. Demonstrating that you have an up‑to‑date vendor risk register, automated patch deployment, and evidence collection (e.g., patch‑install logs) directly supports audit readiness and reduces the likelihood of non‑compliance findings.
Recommended Actions
- Map the control – Align the Zimbra patch to SOC 2 CC6.1 (System Operations) and CC7.2 (Change Management) in your control matrix.
- Validate patch status – Run an inventory scan for ZCS versions < 10.1.20; capture screenshots or log excerpts as evidence.
- Apply the official fix – Upgrade all instances to 10.1.20 or later; verify the patch via checksum.
- Disable exploitable components – If the
zimbra‑snmppackage,snmp_notify, orswatchdogservices are not required, remove or disable them. - Enhance monitoring – Enable SMTP and SNMP logging; forward logs to a SIEM and create alerts for anomalous command execution.
- Update vendor risk register – Record the Zimbra vulnerability, remediation status, and residual risk.
- Document remediation – Retain patch‑deployment records, log‑review findings, and any compensating controls for audit evidence.
Source: https://www.databreachtoday.com/zimbra-exploitation-spreads-as-thousands-unpatched-a-32654