CISA Orders Federal Agencies to Patch Actively Exploited Zimbra Flaw Within Three Days

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. federal agencies to patch an actively exploited vulnerability in the Zimbra Collaboration Suite within three days. The flaw, tracked as CVE-2026-73570, is a command injection weakness in the SNMP monitoring component that allows unauthenticated attackers to achieve remote code execution when SNMP notifications are enabled on a targeted system. Zimbra has already released a fix in version 10.1.20, which shipped on July 20.

CISA's warning follows an alert from CERT Polska, which first flagged the vulnerability as being exploited in the wild. Shadowserver reports that it has identified more than 270 compromised Zimbra instances while scanning for exploitation artifacts, and it tracks over 12,000 Zimbra servers exposed on the Internet, though it remains unclear how many have already been secured. The Polish CERT team advises security teams to review logs for suspicious activity, including unexpected Zimbra service restarts and files created in specific webapps and temp folders by the zimbra user over the past 30 days.

Zimbra Collaboration Suite is widely used by hundreds of millions of users worldwide, including government agencies and thousands of businesses, making it a frequent target for attackers seeking to steal sensitive email data. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and requires Federal Civilian Executive Branch agencies to secure their systems by August 24. The agency has not shared additional details about the ongoing attacks, but urges all organizations running Zimbra, not just federal agencies, to apply the patch promptly.

Read More at the original source →