Exploited in the wild Zimbra Collaboration Suite rce Zimbra zero-day
CISA orders urgent patching of actively exploited Zimbra flaw
CVE Tools coverage
CISA has directed U.S. federal agencies to patch a critical vulnerability in Zimbra Collaboration Suite within three days due to active exploitation in the wild. Tracked as CVE-2026-73570, this command injection flaw in the SNMP monitoring component allows unauthenticated attackers to achieve remote code execution if SNMP notifications are enabled. Zimbra addressed the issue in version 10.1.20, and security teams should update immediately while monitoring for suspicious file creation or service restarts.