CVE Tools
Back to feed
Exploited in the wild Zimbra Collaboration Suite rce Zimbra

Critical Zimbra RCE flaw now actively exploited in attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CERT Polska has confirmed that attackers are actively exploiting a critical remote code execution vulnerability identified as CVE-2026-73570 in the Zimbra Collaboration Suite. This flaw stems from insufficient input sanitization in the SNMP monitoring component, allowing unauthenticated users to execute arbitrary operating system commands when SNMP notifications are enabled. To remediate this issue, Zimbra released version 10.1.20 on July 20. Administrators should urgently apply this update and review system logs for signs of compromise, such as unexpected service restarts or unauthorized file creations within specific Jetty webapp directories.