Researchers have discovered an
OS Command Injection vulnerability (CVE-2026-73570) in Zimbra Collaboration. When the optional package `zimbra-snmp` is installed and SNMP notifications are enabled, an unauthenticated remote attacker can execute arbitrary
OS commands with Zimbra user privileges by sending a specially crafted SMTP request. This vulnerability is actively being exploited, so please verify and apply patches as soon as possible.