CISA orders urgent patching of actively exploited Zimbra flaw

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal government agencies, requiring them to patch a critical vulnerability in Zimbra Collaboration Suite (ZCS) within three days. This latest development comes as part of an ongoing effort to combat cyber threats targeting organizations that rely on the popular email and collaboration platform.

The affected flaw, tracked as CVE-2026-73570, is located in the SNMP monitoring component of ZCS when SNMP notifications are enabled. An unauthenticated attacker can exploit this weakness by sending specially crafted SMTP requests, allowing them to execute arbitrary operating system commands as the Zimbra user. The vulnerability was first discovered and patched by the Zimbra security team on July 20, with version 10.1.20 containing the fix.

However, it appears that attackers have already begun exploiting this flaw in the wild. CERT Polska, the Polish Computer Emergency Response Team (CERT), flagged the vulnerability as being actively targeted last Monday, prompting CISA to take action. Shadowserver, a threat security watchdog, has tracked over 12,000 Zimbra servers exposed on the Internet and has identified more than 270 compromised instances of ZCS while looking for exploitation artifacts related to CVE-2026-73570.

While there is no clear information on the extent of these attacks, CISA’s warning highlights the importance of patching this vulnerability as soon as possible. The agency has added the flaw to its Knowledgebase Error Validation (KEV) catalog and ordered U.S. Federal Civilian Executive Branch agencies to secure their systems by August 24.

ZCS is widely used by hundreds of millions of organizations worldwide, including government agencies and businesses. Unfortunately, Zimbra security issues have become a common target for attackers in recent years. APT28, a state-sponsored threat group linked to Russia’s military intelligence service, has been known to exploit Zimbra vulnerabilities to steal sensitive data from vulnerable email servers.

As we’ve seen in the past, neglecting to patch critical vulnerabilities can lead to catastrophic consequences. With thousands of organizations relying on ZCS for their communication and collaboration needs, it is essential that administrators take immediate action to secure their systems against this threat. The CISA warning serves as a stark reminder that timely patching is crucial in preventing cyber attacks.

In light of this development, we urge all users of Zimbra Collaboration Suite to review their configuration settings and ensure they have applied the latest patches, particularly if SNMP notifications are enabled on their systems. Regularly monitoring system logs for suspicious activity can also help detect potential exploitation attempts. By staying vigilant and taking proactive measures to secure our digital infrastructure, we can reduce the risk of falling victim to these types of attacks.


Source: Bleeping Computer — 2026-08-24