tech β οΈ Zimbra RCE bug is being actively exploited π¨
A critical remote code execution vulnerability, CVE-2026-73570, is being actively exploited in the wild. This flaw affects Zimbra Collaboration Suite deployments where the zimbra-snmp package is installed and SNMP notifications are enabled. The vulnerability allows unauthenticated attackers to run arbitrary OS commands as the zimbra user on affected servers. Zimbra patched this issue in version 10.1.20, released on July 20, 2026, to fix the command injection. Organizations must urgently upgrade or disable SNMP notifications to prevent compromise.