CVE-2026-73570 has been announced as a high-severity vulnerability that could allow remote code execution via the SNMP monitoring component in Zimbra systems. The vulnerability can allow an unauthenticated attacker to execute operations on the operating system side with the privileges of the Zimbra user through specially crafted requests in standard Zimbra versions prior to 10.1.20.
As the Profelis team, following the announcement, we performed the necessary technical reviews on Zimbra Profelis Edition. As a result of the review, it has been verified that Zimbra Profelis Edition is not affected by the CVE-2026-73570 vulnerability. Our customers using Zimbra Profelis Edition do not need to take any action regarding this vulnerability.

Zimbra Profelis Edition is a solution developed independently of standard Zimbra versions, with its architecture and component set determined by Profelis. Therefore, every published vulnerability is evaluated not by version matching, but by being directly tested on the product's own structure. When an impact is detected, the necessary measures are implemented by our team and our customers are notified.
Zimbra Profelis Edition is an end-to-end managed enterprise e-mail solution where security developments are regularly monitored. To review product features, evaluate its compatibility with your existing e-mail infrastructure, or request a demo our product page You can visit.



