← Blog · · df00tech

CISA Adds Zimbra Collaboration Suite Command Injection (CVE-2026-73570) to KEV Catalog

breaking kev Synacor CVE-2026-73570

CISA has added an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS), tracked as CVE-2026-73570, to its Known Exploited Vulnerabilities (KEV) catalog on August 21, 2026. According to Synacor's advisory, the flaw allows an unauthenticated attacker to send specially crafted SMTP requests that can result in execution of arbitrary operating system commands as the Zimbra user.

Why It Matters

ZCS is widely deployed as a self-hosted email and collaboration platform for enterprises, government agencies, and service providers — many of which expose SMTP-facing services to the internet by design. An unauthenticated command injection reachable via SMTP is a severe combination: no credentials are required, and mail transport is inherently internet-facing. KEV inclusion confirms CISA has evidence of active exploitation, meaning this is not theoretical risk. No CVSS score has been published yet, and whether ransomware operators are leveraging this flaw is currently listed as unknown, but unauthenticated RCE-class bugs in mail infrastructure are historically high-value targets for both opportunistic and targeted actors.

What Defenders Should Do Now

  • Identify all internet-facing and internal ZCS instances and confirm patch status against Synacor's advisory as soon as it specifies fixed versions.
  • Where patching cannot happen immediately, consider restricting or closely monitoring inbound SMTP access to Zimbra servers from untrusted sources.
  • Hunt for anomalous child processes spawned by Zimbra service accounts (mailbox/SMTP handler processes launching shells, network utilities, or unexpected binaries).
  • Review mail transport logs for malformed or unusual SMTP command sequences preceding suspicious process activity.
  • Watch for post-exploitation indicators consistent with webshell drops, outbound connections from mail server hosts, or credential access attempts originating from the Zimbra service account.
  • Follow CISA KEV guidance — federal agencies are subject to Binding Operational Directive remediation timelines, and all organizations running ZCS should treat this with equivalent urgency.

Developing Intel

Details are still emerging, including affected version ranges, patch availability, and CVSS scoring. This post will be updated as more information becomes available. For the authoritative advisory, see Zimbra's Security Advisories page.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.