CVE-2026-73570: Zimbra RCE Exploited
ID: 00f014b2-3148-50d3-92e9-df4b724cb7ec
STIX ID: report--00f014b2-3148-50d3-92e9-df4b724cb7ec
Feed Name: SOCRadar Blog
**CVE-2026-73570 — Zimbra RCE (CVSS 8.9):** A pre-authentication command-injection flaw in Zimbra Collaboration Suite's SNMP notification workflow (affecting versions before 10.1.20 when zimbra-snmp, snmp_notify and swatchdog are present) is being actively exploited in the wild; administrators should urgently verify affected configurations, patch to 10.1.20+, review logs and files for indicators of compromise, and investigate potential follow-on activity as commands run as the 'zimbra' user.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
