Zimbra CVE-2026-73570: Unauthenticated SNMP Command Injection Exploited

An unauthenticated OS command injection in Zimbra's SNMP notification path lets attackers run commands as the zimbra user. CERT Polska flagged active exploitation; CISA added CVE-2026-73570 to KEV. Patch ZCS 10.1.20 now.

2026-08-31T22:44:59.114Z
Rudra Verma, Senior Security Architect & Researcher