Zimbra CVE-2026-73570: Unauthenticated SNMP Command Injection Exploited
An unauthenticated OS command injection in Zimbra's SNMP notification path lets attackers run commands as the zimbra user. CERT Polska flagged active exploitation; CISA added CVE-2026-73570 to KEV. Patch ZCS 10.1.20 now.
Rudra Verma, Senior Security Architect & Researcher