CVE-2026-73570 has been announced as a high-severity vulnerability that could allow remote code execution via the SNMP monitoring component in Zimbra systems. The vulnerability can allow an unauthenticated attacker to execute operations on the operating system side with the privileges of the Zimbra user through specially crafted requests in standard Zimbra versions prior to 10.1.20.
As the Profelis team, we conducted the necessary technical assessments on Zimbra Profelis Edition following the announcement. The assessment confirmed that Zimbra Profelis Edition is not affected by the CVE-2026-73570 vulnerability. Customers using Zimbra Profelis Edition do not need to take any action regarding this vulnerability.

Zimbra Profelis Edition is developed independently of standard Zimbra releases, with its architecture and component set defined by Profelis. Therefore, each disclosed vulnerability is assessed through direct testing on the product’s own architecture rather than solely through version matching. If the product is found to be affected, the necessary measures are implemented by our team and our customers are informed.
Zimbra Profelis Edition is an end-to-end managed enterprise email solution in which security developments are monitored regularly. To explore its features, assess its suitability for your existing email infrastructure, or request a demo, visit our product page.



