Junglewise Threat Intelligence

CVE-2026-73570: Zimbra Collaboration Suite OS command injection in SMTP

CVE-2026-73570 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-08-21

Executive brief

Zimbra Collaboration Suite is widely deployed email and collaboration software. An unauthenticated attacker can craft malicious SMTP messages to execute arbitrary system commands on the mail server with the privileges of the Zimbra service account. This vulnerability enables complete server compromise, data theft, and lateral movement within organizational networks.

Technical details

This is an OS command injection vulnerability in Zimbra Collaboration Suite's SMTP message processing component. An unauthenticated remote attacker can send specially crafted SMTP requests that inject operating system commands, leading to arbitrary command execution under the Zimbra service user context. The vulnerability requires no authentication and is reachable via the network on standard SMTP ports. Successful exploitation grants the attacker the ability to execute arbitrary system commands, potentially achieving full server compromise. The vulnerability is known to be actively exploited in the wild as of the disclosure date.

Affected products

  • Zimbra Collaboration Suite <UNKNOWN>

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: exploited: actively exploited in the wild at time of disclosure

Related threats