• News/
  • bleepingcomputer-20260824104512

CISA orders urgent patching of actively exploited Zimbra flaw

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 24, 2026
·
Updated

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The Zimbra security team patched the security flaw (tracked as CVE-2026-73570) in version 10.1.20, released on July 20. Successful exploitation allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled on the targeted system. "Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user," it explained. CISA's warning comes after CERT Polska, the Polish Computer Emergency Response Team (CERT), first flagged the vulnerability as targeted in the wild last Monday. While threat security watchdog Shadowserver tracks more than 12,000 Zimbra servers exposed on the Internet, there is no information on how many are honeypots or have already been secured against attacks exploiting the CVE-2026-73570 flaw. On Monday, Shadowserver also said it has found over 270 compromised Zimbra Collaboration Suite instances while looking for CVE-2026-73570 exploitation artifacts. ​On Friday, CISA confirmed CERT Polska's alert, added the flaw to its KEV catalog, and ordered U.S. Federal Civilian Executive Branch (FCEB...

Read full article

Affected Software

1 affected component
Zimbra Zimbra Collaboration Suite (ZCS)=10.1.20

Frequently Asked Questions

1

Which systems are vulnerable to CVE-2026-73570?

The flaw affects Zimbra Collaboration Suite systems where SNMP notifications are enabled. Successful exploitation can allow an unauthenticated attacker to execute arbitrary operating system commands as the Zimbra user.

2

What patching action has CISA required?

CISA ordered U.S. government agencies to patch the actively exploited flaw within three days. Zimbra fixed CVE-2026-73570 in ZCS version 10.1.20, released on July 20.

3

How is the vulnerability exploited?

The issue is a command injection weakness in SNMP notification processing caused by improper sanitization of untrusted input. An unauthenticated attacker can send specially crafted SMTP requests to trigger command execution when SNMP notifications are enabled.

4

What is known about exploitation and Internet exposure?

CERT Polska first reported the vulnerability as being targeted in the wild last Monday, and CISA has listed it as actively exploited. Shadowserver tracks more than 12,000 Internet-exposed Zimbra servers, though the article does not establish how many are honeypots or already protected against this flaw.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203