CISA orders urgent patching of actively exploited Zimbra flaw

The US government is racing against the clock to patch a critical vulnerability in Zimbra Collaboration Suite (ZCS) after it was discovered that attackers are actively exploiting the flaw. The Cybersecurity and Infrastructure Security Agency (CISA) has ordered all US government agencies to apply the necessary patches within three days, by August 24.

The vulnerability, tracked as CVE-2026-73570, affects Zimbra servers when SNMP notifications are enabled on the system. An attacker can send a specially crafted SMTP request that allows them to execute arbitrary operating system commands with the Zimbra user privileges. This means that an unauthenticated attacker can gain remote code execution without needing any login credentials.

The good news is that the Zimbra security team has already released a patch for this vulnerability in version 10.1.20, which was made available on July 20. However, it’s unclear how many organizations and individuals are still running vulnerable versions of ZCS. Shadowserver, a threat intelligence group, has reported that over 12,000 Zimbra servers are exposed on the internet, although it’s unknown how many of these have already been compromised.

The Polish Computer Emergency Response Team (CERT Polska) first flagged this vulnerability as being actively exploited in the wild last Monday. Since then, CISA has confirmed the alert and added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. This means that US government agencies are under a deadline to patch their systems before August 24.

ZCS is widely used by hundreds of millions of organizations and individuals worldwide, including many government agencies and businesses. Unfortunately, Zimbra security issues have been targeted by attackers in the past, with notable examples including APT28 (a state-sponsored threat group linked to Russia’s military intelligence service) exploiting a stored cross-site scripting vulnerability in attacks targeting Ukrainian government ZCS servers.

Given the severity of this vulnerability and the fact that it is being actively exploited, all users of Zimbra Collaboration Suite should take immediate action to protect their systems. This means patching your ZCS installation as soon as possible, even if you’re not running the vulnerable version. It’s also essential to monitor your system logs for suspicious activity and be on the lookout for any signs that an attacker has compromised your server.

In conclusion, it’s crucial for all organizations and individuals using Zimbra Collaboration Suite to take this vulnerability seriously and apply the necessary patches as soon as possible. Remember to stay vigilant and keep your systems up-to-date with the latest security patches to prevent these types of attacks from succeeding in the future.


Source: Bleeping Computer — 2026-08-24