{"id":6049,"date":"2026-10-01T10:51:08","date_gmt":"2026-10-01T15:51:08","guid":{"rendered":"https:\/\/cert.pa\/?p=6049"},"modified":"2026-10-01T10:51:09","modified_gmt":"2026-10-01T15:51:09","slug":"csirt-panama-aviso-2026-oct-1-vulnerabilidad-alta-en-synacor-zimbra-collaboration-suite-que-permite-ejecucion-remota-de-codigo-cve-2026-73570","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=6049","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2026-oct-1: Vulnerabilidad Alta en Synacor Zimbra Collaboration Suite que permite ejecuci\u00f3n remota de c\u00f3digo \u2014 CVE-2026-73570"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Fecha de emisi\u00f3n:<\/strong> 1 de octubre de 2026<br><strong>CVE ID:<\/strong> CVE-2026-73570<br><strong>Severidad:<\/strong> ALTA \u2014 CVSS 3.1: 8.9<br><strong>Vector CVSS:<\/strong> CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:L<br><strong>Tipo de vulnerabilidad:<\/strong> CWE-78: Inyecci\u00f3n de comandos del sistema operativo<br><strong>Producto afectado:<\/strong> Synacor Zimbra Collaboration Suite<br><strong>Explotaci\u00f3n activa:<\/strong> S\u00ed \u2014 Reportada por SecurityWeek, The Hacker News, Microsoft Security Blog<br><strong>Fuente:<\/strong> NVD \/ SecurityWeek \/ The Hacker News \/ Microsoft Security Blog<br><strong>Clasificaci\u00f3n TLP:<\/strong> TLP:CLEAR (Difusi\u00f3n p\u00fablica)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>I. Descripci\u00f3n<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Se ha identificado una vulnerabilidad de inyecci\u00f3n de comandos del sistema operativo en Synacor Zimbra Collaboration Suite, registrada como CVE-2026-73570 y calificada con 8.9 de 10 en la escala CVSS 3.1. Un atacante que la aproveche podr\u00eda lograr la ejecuci\u00f3n remota de c\u00f3digo.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SecurityWeek, The Hacker News y Microsoft Security Blog reportan que la vulnerabilidad ya est\u00e1 siendo explotada.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Descripci\u00f3n t\u00e9cnica publicada en NVD (en ingl\u00e9s): \u00abA remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.\u00bb<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>II. Productos Afectados<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Producto<\/th><th class=\"has-text-align-left\" data-align=\"left\">Versiones afectadas<\/th><th class=\"has-text-align-left\" data-align=\"left\">Versi\u00f3n corregida<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">Synacor Zimbra Collaboration Suite<\/td><td class=\"has-text-align-left\" data-align=\"left\">Anteriores a 10.1.20<\/td><td class=\"has-text-align-left\" data-align=\"left\">10.1.20 o superior<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>III. Acciones Requeridas<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Actualizar inmediatamente<\/strong><br>Actualizar Synacor Zimbra Collaboration Suite a la versi\u00f3n 10.1.20 o superior, seg\u00fan la rama instalada.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Mitigar inmediatamente si no es posible parchear<\/strong><br>Mientras se realiza la actualizaci\u00f3n, restringir el acceso desde Internet a la interfaz o servicio afectado, permitiendo \u00fanicamente las direcciones de confianza que lo necesiten, y aplicar las mitigaciones indicadas por el fabricante.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Verificar posible compromiso<\/strong><br>El parche cierra el vector de explotaci\u00f3n, pero no elimina un acceso que el atacante ya haya obtenido. Revisar los registros y el sistema en busca de actividad inusual desde antes de la actualizaci\u00f3n (cuentas nuevas, archivos o procesos desconocidos, conexiones salientes no habituales) siguiendo la gu\u00eda de la secci\u00f3n IV, y reportar cualquier hallazgo a incidentes@cert.pa.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>IV. Gu\u00eda de Verificaci\u00f3n de Compromiso<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CSIRT Panam\u00e1 pone a disposici\u00f3n una gu\u00eda para que los administradores de Zimbra comprueben si sus servidores han sido afectados por la explotaci\u00f3n de CVE-2026-73570. Se recomienda aplicarla en todos los servidores Zimbra expuestos, incluso si ya fueron actualizados a la versi\u00f3n 10.1.20.<\/p>\n\n\n\n<div class=\"wp-block-file\"><a id=\"wp-block-file--media-guia-73570\" href=\"https:\/\/cert.pa\/wp-content\/uploads\/2026\/10\/Guia_Verificacion_Compromiso_CVE-2026-73570.docx\">Gu\u00eda de Verificaci\u00f3n de Compromiso \u2014 CVE-2026-73570 (Word)<\/a><a href=\"https:\/\/cert.pa\/wp-content\/uploads\/2026\/10\/Guia_Verificacion_Compromiso_CVE-2026-73570.docx\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-guia-73570\">Descargar<\/a><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>V. Referencias<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Fabricante. Aviso de seguridad. <a href=\"https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Security_Advisories\">https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Security_Advisories<\/a><\/li>\n\n\n\n<li>CERT Polska (moje.cert.pl). An\u00e1lisis y mitigaci\u00f3n. <a href=\"https:\/\/moje.cert.pl\/komunikaty\/2026\/145\/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite\/\">https:\/\/moje.cert.pl\/komunikaty\/2026\/145\/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite\/<\/a><\/li>\n\n\n\n<li>National Institute of Standards and Technology (NIST). National Vulnerability Database: CVE-2026-73570. <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-73570\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-73570<\/a><\/li>\n\n\n\n<li>SecurityWeek. Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure. <a href=\"https:\/\/www.securityweek.com\/zimbra-vulnerability-exploited-in-the-wild-prior-to-public-disclosure\/\">https:\/\/www.securityweek.com\/zimbra-vulnerability-exploited-in-the-wild-prior-to-public-disclosure\/<\/a><\/li>\n\n\n\n<li>The Hacker News. Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets. <a href=\"https:\/\/thehackernews.com\/2026\/09\/attackers-exploit-zimbra-flaw-to-deploy.html\">https:\/\/thehackernews.com\/2026\/09\/attackers-exploit-zimbra-flaw-to-deploy.html<\/a><\/li>\n\n\n\n<li>Microsoft Security Blog. Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570. <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/30\/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570\/\">https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/30\/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570\/<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>VI. Informaci\u00f3n de Contacto<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CSIRT PANAM\u00c1 \u00b7 Computer Security Incident Response Team<br>Autoridad Nacional para la Innovaci\u00f3n Gubernamental<br>E-Mail: incidentes@cert.pa \u00b7 info@cert.pa<br>Tel\u00e9fono: +507 520-CERT (2378) \u00b7 Web: https:\/\/cert.pa \u00b7 X: @CSIRTPanama \u00b7 Key ID: 16F2B124<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fecha de emisi\u00f3n: 1 de octubre de 2026CVE ID: CVE-2026-73570Severidad: ALTA \u2014 CVSS 3.1: 8.9Vector CVSS: CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:LTipo de vulnerabilidad: CWE-78: [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":5256,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4],"tags":[76,72,68,153],"class_list":["post-6049","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad","tag-actualizaciones","tag-avisos-de-seguridad","tag-vulnerabilidades","tag-zimbra","severidad-alto"],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/6049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6049"}],"version-history":[{"count":1,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/6049\/revisions"}],"predecessor-version":[{"id":6050,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/6049\/revisions\/6050"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/5256"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}