Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

[KEV] CVE-2026-73570 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2026-73570 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2026-73570 is an unauthenticated OS command injection vulnerability in Synacor Zimbra Collaboration Suite that can be reached through specially crafted SMTP requests.

Technical Detail

The flaw allows attacker-controlled SMTP input to be processed in a manner that permits operating system command injection. An unauthenticated remote attacker may send crafted SMTP requests and cause arbitrary commands to execute as the Zimbra user. Successful exploitation can provide remote code execution within the privileges of the Zimbra service account.

Exploitation Status

Exploit maturity is assessed as Operational, indicating that exploitation capability is usable in real-world attacks rather than limited to a conceptual proof of concept. CISA has confirmed active exploitation in the wild. The vulnerability was added to the CISA Known Exploited Vulnerabilities Catalog on August 21, 2026.

Who Is Targeting This

Reported (research-inferred): Public reporting describes the vulnerability as being used in active ransomware campaigns, but no specific ransomware operation or ATT&CK group has been publicly identified. There is no confirmed public threat actor attribution at this time.

What To Do

Apply Synacor Zimbra Collaboration Suite security updates addressing CVE-2026-73570 immediately, prioritizing internet-accessible mail servers. Federal Civilian Executive Branch agencies should patch by the CISA-specified KEV remediation deadline or apply mitigations in accordance with CISA Binding Operational Directive 22-01; the specific deadline is not included in the available data. Where immediate patching is not possible, restrict SMTP access to required sources where operationally feasible, limit unnecessary exposure of Zimbra services, and closely monitor Zimbra hosts for suspicious child processes, shell execution, unexpected outbound connections, and anomalous activity under the Zimbra user account.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →