Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Zimbra Collaboration RCE Under Active Exploitation (CVE‑2026‑73570)

A high-severity vulnerability (CVE-2026-73570) has been identified in Zimbra Collaboration Suite (ZCS) and is currently being actively exploited. The vulnerability affects Zimbra systems with SNMP notifications enabled and could allow an unauthenticated remote attacker to execute unauthorized system commands with Zimbra user privileges on an affected server.
 
Affected Systems:
  • Zimbra Collaboration Suite (ZCS): versions earlier than 10.1.20 are affected when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
 
Security Risks
 
Successful exploitation could allow an attacker to execute commands with Zimbra user privileges, potentially resulting in unauthorized access, exposure or loss of data, service disruption, or further compromise of the Zimbra environment.
 
For additional information on Zimbra security updates and available patches, please refer to the official Zimbra Product News.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
  • Upgrade affected Zimbra Collaboration Suite (ZCS) installations to version 10.1.20 or above, particularly systems with the optional zimbra-snmp package installed and SNMP notifications enabled.
  • Before applying updates, ensure that a current and verified backup is available and can be restored if needed.
  • For additional details on recommended mitigation measures, refer to CERT Polska Recommendations.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

25 August 2026

© 2026 National Cyber Security Authority