CERT Polska has reported active exploitation of a critical vulnerability (CVE-2026-73570) in the Zimbra Collaboration Suite, which allows unauthenticated remote code execution (RCE). The flaw, confirmed as being exploited shortly after a patch was issued on July 20, 2026, specifically affects systems with enabled SNMP trap notifications and the swatchdog service, both of which are set by default.
Administrators are advised to check logs for signs of exploitation and verify file creation by the zimbra user in certain directories. With over 12,100 Zimbra servers potentially reachable online, the vulnerability presents a significant risk, particularly for organizations targeted by state-backed actors.