Exploited in the wild Zimbra Collaboration Suite rce Zimbra
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
CVE Tools coverage
CERT Polska has confirmed active in-the-wild exploitation of CVE-2026-73570, a high-severity command injection vulnerability in Zimbra Collaboration Suite versions prior to 10.1.20. The flaw affects installations where the zimbra-snmp package is present and allows unauthenticated attackers to execute arbitrary OS commands by sending crafted SMTP requests that bypass input sanitization during SNMP notification handling. While Zimbra released a patch for this issue in July, the recent confirmation of real-world attacks underscores the urgent need for organizations to verify they have upgraded to version 10.1.20 and should inspect system logs for signs of compromise.