Email-Security
CVE-2026-73570: Unauthenticated Zimbra RCE via SNMP Notifications Under Active Exploitation
CERT Polska confirms in-the-wild exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration's SNMP notification handling — patched in 10.1.20, but plenty of mail servers haven't updated.
Zimbra Patches Classic Web Client Stored XSS Reported by Google TAG
Zimbra shipped 10.1.19 to fix an unauthenticated stored XSS in the Classic Web Client, reachable by simply opening a crafted email — no CVE assigned yet, reported by Google's Threat Analysis Group.