Security3 min read
CISA puts an exploited Zimbra command-injection bug on the KEV list
CVE-2026-73570 is unauthenticated command injection in SNMP notification processing as the zimbra user. CERT Polska saw it in the wild. Federal agencies had to patch by August 24.
