CVE-2026-73570: critical Zimbra RCE actively exploited in the wild

An unauthenticated remote code execution vulnerability in Zimbra Collaboration Suite (CVE-2026-73570, CVSS 8.9) is under active exploitation via SMTP and SNMP notifications, affecting versions prior to 10.1.20. CISA and CERT Polska confirmed real-world attacks as of 21 August 2026.

6 reportsother · primary

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-73570 is exploited in the wild. This unauthenticated RCE hits Zimbra Collaboration via SNMP notifications. Patch to 10.1.20 now. # Zimbra # CVE # RCE # RemoteCodeExecution # ExploitedInTheWil

mastodon:infosec-exchangeother40d ago kagi ↗

CVE-2026-73570 is exploited in the wild. This unauthenticated RCE hits Zimbra Collaboration via SNMP notifications. Patch to 10.1.20 now. # Zimbra # CVE # RCE # RemoteCodeExecution # ExploitedInTheWild # InfoSec # PatchNow https:// securityonline.info/zimbra-cve -2026-73570/?utm_source=mastodon&utm_medium=jetpack_social

CRITICAL: CVE-2026-73570 in Zimbra Collaboration Suite is under active exploit. RCE via SNMP notifications lets unauth attackers run OS commands as Zimbra user. Patch to 10.1.20 now & monitor for abno

mastodon:infosec-exchangeother40d ago kagi ↗

CRITICAL: CVE-2026-73570 in Zimbra Collaboration Suite is under active exploit. RCE via SNMP notifications lets unauth attackers run OS commands as Zimbra user. Patch to 10.1.20 now & monitor for abnormal files/restarts. Details: https:// radar.offseq.com/threat/critic al-zimbra-rce-flaw-now-actively-exploited-in-attacks-7db25eca9fa27ac1 # OffSeq # Zimbra # Vuln

Active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite is underway. The command injection flaw enables unauthenticated RCE on ZCS versions prior to 10.1.20 when zimbra-snmp is installed w

mastodon:infosec-exchangeother40d ago kagi ↗

Active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite is underway. The command injection flaw enables unauthenticated RCE on ZCS versions prior to 10.1.20 when zimbra-snmp is installed with SNMP notifications active. Attackers exploit this via crafted SMTP requests for full server compromise. Patch or disable SNMP immediately. # ZimbraRCE # CVE202673570 # PatchNow https:// cyberworld

CVE-2026-73570 in Zimbra Collaboration Suite is under active exploitation. CERT Polska flagged real-world attacks this week. The flaw grants unauthenticated remote OS command execution when zimbra-snm

mastodon:infosec-exchangeother40d ago kagi ↗

CVE-2026-73570 in Zimbra Collaboration Suite is under active exploitation. CERT Polska flagged real-world attacks this week. The flaw grants unauthenticated remote OS command execution when zimbra-snmp is installed with SNMP enabled. Attacker identity and campaign goals remain unknown — patch priority is critical for affected deployments. # Zimbra # CVE202673570 # ThreatIntelligence # PatchNow htt

CVE-2026-73570: Synacor Zimbra Collaboration Suite (ZCS) — Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

json:cisa-kevprimary39d ago kagi ↗

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on

🔴 EXPLOITED Zimbra Collaboration Suite has a critical flaw (CVE-2026-73570, CVSS 8.9): an unauthenticated attacker runs commands on the mail server, sent over SMTP. Exploited now, on CISA's must-patc

mastodon:infosec-exchangeother39d ago kagi ↗

🔴 EXPLOITED Zimbra Collaboration Suite has a critical flaw (CVE-2026-73570, CVSS 8.9): an unauthenticated attacker runs commands on the mail server, sent over SMTP. Exploited now, on CISA's must-patch list. Fix: upgrade to 10.1.20. 10.1.19 is not enough. https:// suriq.io/blog/zimbra-snmp-rce- cve-2026-73570 # CVE # CISAKEV # infosec # cybersecurity