Exploited in the wild Zimbra Collaboration Suite rce Synacor network-edge
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
CVE Tools coverage
Shadowserver reports that at least 274 internet-exposed Zimbra Collaboration Suite instances have been breached through active exploitation of CVE-2026-73570. This unauthenticated code injection vulnerability impacts installations using the optional zimbra-snmp package with SNMP notifications enabled, allowing attackers to execute arbitrary OS commands.
Synacor released a patch in version 10.1.20 on July 20, 2026, and CISA has now added the issue to its Known Exploited Vulnerabilities catalog, mandating remediation for federal agencies. With thousands of potentially vulnerable systems still unpatched, administrators are urged to apply the update immediately and audit their systems for signs of intrusion.