[KEV] CVE-2026-73570 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-73570 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-73570 is an unauthenticated OS command injection vulnerability in Synacor Zimbra Collaboration Suite that can be reached through specially crafted SMTP requests.
Technical Detail
The flaw allows attacker-controlled SMTP input to be processed in a manner that permits operating system command injection. An unauthenticated remote attacker may send crafted SMTP requests and cause arbitrary commands to execute as the Zimbra user. Successful exploitation can provide remote code execution within the privileges of the Zimbra service account.
Exploitation Status
Exploit maturity is assessed as Operational, indicating that exploitation capability is usable in real-world attacks rather than limited to a conceptual proof of concept. CISA has confirmed active exploitation in the wild. The vulnerability was added to the CISA Known Exploited Vulnerabilities Catalog on August 21, 2026.
Who Is Targeting This
Reported (research-inferred): Public reporting describes the vulnerability as being used in active ransomware campaigns, but no specific ransomware operation or ATT&CK group has been publicly identified. There is no confirmed public threat actor attribution at this time.
What To Do
Apply Synacor Zimbra Collaboration Suite security updates addressing CVE-2026-73570 immediately, prioritizing internet-accessible mail servers. Federal Civilian Executive Branch agencies should patch by the CISA-specified KEV remediation deadline or apply mitigations in accordance with CISA Binding Operational Directive 22-01; the specific deadline is not included in the available data. Where immediate patching is not possible, restrict SMTP access to required sources where operationally feasible, limit unnecessary exposure of Zimbra services, and closely monitor Zimbra hosts for suspicious child processes, shell execution, unexpected outbound connections, and anomalous activity under the Zimbra user account.