Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw Found in Zimbra Email Software

A serious security weakness has been found in Zimbra Collaboration software that could allow attackers to take control of affected systems remotely. This matters because Zimbra is commonly used for business email and collaboration, and the flaw can be exploited without needing to log in.

21 August 2026

Reference: CVE-2026-73570

1. What is being reported?

The report describes a vulnerability in Zimbra Collaboration versions before 10.1.20 when a specific optional feature called zimbra-snmp is installed and SNMP notifications are turned on. Attackers can send specially crafted messages that trick the system into running harmful commands without any authentication.

2. What this means in plain English

If your organisation uses Zimbra with this optional feature enabled, attackers could potentially take over your email server, access sensitive information, or disrupt your services. This risk is significant because it does not require the attacker to have a username or password.

3. Could this affect a small business?

Small businesses or charities using Zimbra Collaboration with the zimbra-snmp package and SNMP notifications enabled may be affected. If you do not use Zimbra or do not have this optional feature active, you are unlikely to be impacted.

4. What to do now

  • Check if your organisation uses Zimbra Collaboration software and confirm the version.
  • Ask your IT provider if the zimbra-snmp package and SNMP notifications are enabled on your system.
  • If affected, apply any security updates or patches provided by Zimbra immediately.
  • If you cannot update promptly, consider disabling the zimbra-snmp package or SNMP notifications until a fix is applied.

5. Ask your IT provider

Can you confirm whether our Zimbra Collaboration server has the zimbra-snmp package installed with SNMP notifications enabled, and if so, has it been updated to fix the recent remote code execution vulnerability?

6. Bottom line

If you use Zimbra with the SNMP feature enabled, act quickly to update or disable it to protect your organisation from serious cyberattacks.

Information based on CISA KEV, NVD, and reputable security news reports.

Back to Vulnerability Briefs