CVE-2026-73570 Zimbra KEV: PoC 97/100 Readiness
Our analysts triaged one public artifact out of the two we track for CVE-2026-73570, and a CISA KEV listing confirms in-the-wild exploitation is occurring. Our 97 out of 100 triage score describes only the quality of the one public exploit artifact we examined, not a measurement of that confirmed exploitation. We record this data as of 2026-08-25 regarding the CVSS 8.9 High vulnerability in Synacor Zimbra Collaboration Suite (ZCS). The federal remediation deadline of the 24th passed yesterday, placing all vulnerable instances in an active state of non-compliance with confirmed threat activity.
Artifact Triage Yields Maximum Risk Metrics
Our tracking records exploitation activity in the wild for this vulnerability across two tracked exploit artifacts. Out of these two artifacts, our analysts extracted and evaluated a single public sample to gauge its mechanical viability. We assign this specific artifact a near-maximum score of 97 out of 100 in our triage. We derive this verdict by weighing four specific evaluation criteria: ease of use, potential impact, spread capability, and whether special access or user interaction is needed.
The public PoC we analyzed targets Zimbra Collaboration Suite < 10.1.20. Addressing the ease of use and user interaction criteria, the artifact triggers the vulnerability using a direct network request without demanding prerequisites. This PoC demonstrates an OS command injection in Zimbra Collaboration Suite via the SNMP trap handler exposed at the backup extension endpoint. The execution sequence requires no complex authentication bypass routines, and the target user does not need to execute a payload. The code simply crafts a malicious snmp_notify payload containing a shell-injection vector and issues an HTTP GET request to trigger command execution on the target.
The high triage verdict heavily weights this snmp_notify mechanism because issuing an HTTP GET request represents a low barrier for attackers targeting Zimbra infrastructure. This method succeeds by exposing potential unauthenticated or easily-accessible execution on the targeted server. Evaluating the potential impact, the resulting OS command injection grants the attacker immediate execution capabilities on the host running the Zimbra Collaboration Suite, eliminating the need for subsequent exploitation steps to gain initial control.
When assessing spread capability, the dependency on the backup extension endpoint defines the exposed attack surface. Any instance running the affected version of Zimbra Collaboration Suite with this endpoint accessible presents a viable target for this specific code. We explicitly restrict our technical description to these exact vectors, as the provided intelligence lacks additional details on the mechanism. Defenders mapping the vulnerability must rely on the SNMP trap handler, the snmp_notify payload, and the backup extension endpoint parameters described here.
For related coverage, see CVE-2026-50522 SharePoint KEV RCE: PoC Still Immature.
Operational Chatter Matches KEV Confirmation
We logged three references to CVE-2026-73570 on actor-operated Telegram channels in the last seven days, while recording zero mentions on breach forums during the same window. The split between the three Telegram references and zero breach forum posts isolates where active discussion of this Zimbra vulnerability resides. Defenders monitoring only traditional breach forums observe an absence of signal, but that zero count confirms only a lack of public underground discussion on those specific platforms, not a lack of threat activity.
The three Telegram references confirm that actors discuss Zimbra Collaboration Suite targeting in operational channels, outside the view of standard forum scraping. This focused communication supports the external confirmation of active threats. CISA added CVE-2026-73570 to the Known Exploited Vulnerabilities catalog on the 21st, which confirms in-the-wild exploitation. Our news tracking separately records four public news reports covering the threat, and we separately track that a working exploit is available for this vulnerability.
The gap between the target version of our analyzed sample and the full range of vulnerable software is an important distinction. We describe this as the version the public exploit was written against, not as the authoritative affected range. Defenders must verify the authoritative affected range via the vendor advisory. The CISA KEV entry references a vendor advisory for this CVE, confirming that remediation guidance is publicly available. Organizations possess all necessary resources to determine their actual exposure across all deployed versions.
For related coverage, see CVE-2026-31431 Linux Root Exploit in CISA KEV (CVSS 7.8).
Required Detection and Remediation Actions
The existence of a public vendor advisory and the active exploitation status dictate an immediate response path.
- Apply vendor advisory patches for CVE-2026-73570: The federal remediation deadline has already passed, meaning all vulnerable instances of Zimbra Collaboration Suite are operating out of compliance under conditions of confirmed in-the-wild exploitation.
- Inspect traffic targeting the backup extension endpoint: Defenders must scrutinize network logs for HTTP GET requests aimed at the backup extension endpoint that contain
snmp_notifypayloads, as our high triage verdict reflects the ease of executing OS command injection vectors through this exact path.
Immediate Remediation Mandate
Security teams must execute patching and mitigation protocols in a strict sequence based on the lapsed timeline. The remediation deadline established by CISA mandates that all instances of Zimbra Collaboration Suite across the environment receive the vendor patch immediately. The presence of our near-maximum readiness verdict in one of our two tracked artifacts, alongside three Telegram mentions in the last seven days, removes any justification for delay. No asset running the affected software is permitted to wait past this deadline under confirmed exploitation conditions. Teams execute the patch application first across all servers regardless of their network placement, because the KEV listing dictates universal urgency. Following immediate patch deployment, organizations evaluate historical network logs, utilizing the HTTP GET request and snmp_notify payload characteristics to identify prior compromise attempts against the backup extension endpoint.
Analysis produced by the Purple-Ops threat intelligence team from our own platform monitoring of 400+ leak sites and underground sources.