A command injection in Zimbra’s SNMP component is exploited via plain email and joins the KEV
CVE-2026-73570, an OS command injection in Zimbra Collaboration’s SNMP component, is under active exploitation and joined CISA’s KEV catalog on August 21, 2026, with a federal due date of August 24. Patch to 10.1.20 and hunt the intruder in the logs, not just the patch.