21 August 2026
Reference: CVE-2026-73570
1. What is being reported?
The report describes a vulnerability in Zimbra Collaboration versions before 10.1.20 when a specific optional feature called zimbra-snmp is installed and SNMP notifications are turned on. Attackers can send specially crafted messages that trick the system into running harmful commands without any authentication.
2. What this means in plain English
If your organisation uses Zimbra with this optional feature enabled, attackers could potentially take over your email server, access sensitive information, or disrupt your services. This risk is significant because it does not require the attacker to have a username or password.
3. Could this affect a small business?
Small businesses or charities using Zimbra Collaboration with the zimbra-snmp package and SNMP notifications enabled may be affected. If you do not use Zimbra or do not have this optional feature active, you are unlikely to be impacted.
4. What to do now
- Check if your organisation uses Zimbra Collaboration software and confirm the version.
- Ask your IT provider if the zimbra-snmp package and SNMP notifications are enabled on your system.
- If affected, apply any security updates or patches provided by Zimbra immediately.
- If you cannot update promptly, consider disabling the zimbra-snmp package or SNMP notifications until a fix is applied.
5. Ask your IT provider
Can you confirm whether our Zimbra Collaboration server has the zimbra-snmp package installed with SNMP notifications enabled, and if so, has it been updated to fix the recent remote code execution vulnerability?
6. Bottom line
If you use Zimbra with the SNMP feature enabled, act quickly to update or disable it to protect your organisation from serious cyberattacks.
Information based on CISA KEV, NVD, and reputable security news reports.