CVE-2026-73570 is a command injection vulnerability in Zimbra Collaboration (ZCS) before 10.1.20, with a CVSS score of 8.9. When the optional zimbra-snmp package is installed and SNMP notifications are enabled, an unauthenticated attacker can send specially crafted SMTP requests to execute arbitrary OS commands as the Zimbra user. The flaw is actively exploited in the wild, and CERT Polska has issued mitigation guidance.