CVE-2026-73570 · High · CISA KEV
Zimbra OS Command Injection: Unauthenticated RCE via Malicious SMTP Requests
Threat Engine Auto-Feed · data current as of 2026-08-22
A critical OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) allows unauthenticated attackers to execute arbitrary operating system commands. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog. Organizations using ZCS are at high risk of remote code execution.
- CVSS:
- EPSS percentile: 0.43183
- Exploitation pressure: 51/100 (High)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 43th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability involves an operating system command injection. It means that an attacker can embed malicious commands within data that is processed by the system, tricking the software into executing those commands directly on the underlying operating system. In this case, specially crafted SMTP requests are the vector.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations utilizing Zimbra Collaboration Suite (ZCS)
- Enterprises with internet-facing ZCS instances
Misconfigurations that escalate it
- Lack of robust network segmentation for ZCS deployments
- Insufficient monitoring of SMTP traffic for anomalous patterns
High-impact scenarios
- Unauthenticated remote code execution on the ZCS server
- Full compromise of the ZCS environment and potential lateral movement
- Data exfiltration or disruption of email services
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor ZCS server logs for unusual process execution or command line activity originating from the Zimbra user
- Inspect SMTP traffic for malformed or suspicious requests targeting ZCS
- Look for unexpected outbound connections from the ZCS server
Contain
- Isolate affected ZCS instances from the network if compromise is suspected
- Block suspicious IP addresses communicating with ZCS SMTP services
Patch
- Apply the latest security patches and updates for Zimbra Collaboration Suite (ZCS) immediately
Frontier verdict — High
High priority due to active exploitation in the wild (CISA KEV) and potential for unauthenticated remote code execution.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.