CVE Tools
Back to feed
Exploited in the wild Zimbra Collaboration Suite rce Zimbra zero-day

CISA orders urgent patching of actively exploited Zimbra flaw

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA has directed U.S. federal agencies to patch a critical vulnerability in Zimbra Collaboration Suite within three days due to active exploitation in the wild. Tracked as CVE-2026-73570, this command injection flaw in the SNMP monitoring component allows unauthenticated attackers to achieve remote code execution if SNMP notifications are enabled. Zimbra addressed the issue in version 10.1.20, and security teams should update immediately while monitoring for suspicious file creation or service restarts.