Zimbra Collaboration Suite Vulnerability Exploited in Attacks

A high-severity vulnerability in Zimbra Collaboration Suite (ZCS), CVE-2026-73570, is being actively exploited in attacks. It allows an unauthenticated attacker to remotely execute arbitrary code (RCE) on the vulnerable server. The vulnerability is related to insufficient input validation during SNMP message processing. The attack is possible if the server has the optional zimbra-snmp package installed and SNMP notifications enabled. By sending a specially crafted SMTP request, the attacker can achieve arbitrary operating system command execution with Zimbra user privileges. More information: https://nvd.nist.gov/vuln/detail/cve-2026-73570

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source