Rapid7 Finds Zimbra Can Rewrite Collaboration Trust
Rapid7 and Zimbra disclosed more than 50 flaws in Zimbra Collaboration Suite, including CVE-2026-73570 in the optional zimbra-snmp package. Rapid7 says some of the bugs go beyond mailbox theft and let an attacker impersonate senders, control inbox visibility, and alter shared documents and calendars without credentials.
That shifts the problem from access to integrity. If a suite trusts a forged message or calendar change as real, attackers can rewrite approvals and records that other users will act on later, so the damage can survive the initial compromise and look legitimate after the fact.
For organizations that run Zimbra as part of email-driven business processes, the exposure sits in the collaboration layer itself: mail, calendars, and shared records become part of the attack surface. CVE-2026-73570 is already in CISA’s Known Exploited Vulnerabilities catalog, so this is not just a patch-note issue; it is a trust problem with operational fallout.
CVSS 8.9 HIGH: a remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. EPSS 12% (96th percentile).
CISA federal remediation date Aug 24 · date passed
This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite.