What happened
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Affected versions
Zimbra Collaboration Suite (ZCS): See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-Intel · gabrielunknown/CVE-2026-73570Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)RCEPerl★ 1⑂ 0Code indexedUpdated 26 Aug 2026gabrielunknown2026-08-26CandidateCVE-Intel · BiuTrap/CVE-2026-73570CVE-2026-73570 PoCPoC★ 0⑂ 0Updated 25 Aug 2026BiuTrap2026-08-24CandidateCVE-Intel · HORKimhab/CVE-2026-73570CVE-2026-73570ExploitPython★ 5⑂ 1Code indexedUpdated 25 Aug 2026HORKimhab2026-08-21CandidateCVE-Intel · jishino567/CVE-2026-73570PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)InjectionPython★ 1⑂ 0Code indexedUpdated 25 Aug 2026Tags: cve-2026-73570, exploit, zimbra, zimbra-exploitjishino5672026-08-25CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.