
The Cybersecurity and Infrastructure Safety Company (CISA) has ordered U.S. authorities businesses to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) inside three days.
The Zimbra safety group patched the safety flaw (tracked as CVE-2026-73570) in version 10.1.20, launched on July 20.
Profitable exploitation permits unauthenticated attackers to realize distant code execution by exploiting a command injection weak spot within the SNMP monitoring element when SNMP notifications are enabled on the focused system.
“Resulting from improper sanitization of untrusted enter throughout SNMP notification processing, an unauthenticated attacker can ship specifically crafted SMTP requests that will end in execution of arbitrary working system instructions because the Zimbra consumer,” it defined.
CISA’s warning comes after CERT Polska, the Polish Pc Emergency Response Crew (CERT), first flagged the vulnerability as focused within the wild final Monday.
Whereas risk safety watchdog Shadowserver tracks more than 12,000 Zimbra servers uncovered on the Web, there is no such thing as a info on what number of are honeypots or have already been secured in opposition to assaults exploiting the CVE-2026-73570 flaw.
On Monday, Shadowserver also said it has discovered over 270 compromised Zimbra Collaboration Suite instances whereas in search of CVE-2026-73570 exploitation artifacts.

On Friday, CISA confirmed CERT Polska’s alert, added the flaw to its KEV catalog, and ordered U.S. Federal Civilian Govt Department (FCEB) businesses to safe their methods inside three days, by August 24.
Though CISA did not share any info on these ongoing assaults, the Polish CERT group requested safety groups to verify logs for suspicious exercise, such because the Zimbra service restarting unexpectedly, and for information created within the /choose/zimbra/jetty/webapps/, /choose/zimbra/jetty_base/webapps/, and /tmp/ folders by consumer zimbra during the last 30 days.
ZCS is a well-liked e mail and collaboration suite utilized by tons of of hundreds of thousands of organizations and other people worldwide, together with tons of of presidency businesses and 1000’s of companies.
Zimbra safety points are generally focused within the wild and have been used to steal delicate knowledge from weak e mail servers in recent times.
Most just lately, Seqrite Labs researchers revealed in March that APT28 (a state-sponsored risk group linked to Russia’s army intelligence service) was exploiting a saved cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers.
In October 2024, U.S. and UK cyber businesses warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear) linked to Russia’s International Intelligence Service had been targeting Zimbra servers utilizing a flaw beforehand exploited to steal email account credentials.
Russian Winter Vivern cyber spies have additionally abused a mirrored Cross-Website Scripting (XSS) vulnerability to steal emails belonging to NATO-aligned people and organizations through Zimbra webmail portals.
General prevention scores can disguise what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses method by method throughout 338 million simulations run in buyer manufacturing environments.

