CERT Polska, Poland's national computer emergency response team, reported on 17 August that CVE-2026-73570 was being exploited against Zimbra Collaboration Suite 1. The flaw lets an attacker who has not logged in run the operating system's own commands as the Zimbra user, the account the mail platform itself runs under, wherever Simple Network Management Protocol notification and swatchdog are switched on. SNMP is the protocol network kit uses to report its own health; swatchdog watches log files and fires an action when a pattern appears.
It scores 8.9, and Zimbra fixed it in release 10.1.20 2. Neither of those two features is mail. Both are the kind of operational plumbing an administrator switches on once during commissioning, and a shop that inventories its mail platform by version number will not have recorded whether either is enabled.
This has nothing in common with the zero-click webmail chain that fifteen agencies wrote up in July, which fired when a target merely previewed a message . That advisory told administrators to patch the appliance. This one asks a different question, namely which optional components are running on it, and the answer is not in any patch level.
The Canadian Centre for Cyber Security issued its own advisory on the same flaw four days later 3. Two national bodies on opposite sides of the Atlantic reached the same conclusion within a week, from a Polish alert written in Polish, which is roughly how fast a CERT-to-CERT signal travels when the underlying product is widely deployed.
