CISA Orders U.S. Agencies to Patch Actively Exploited Zimbra Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in the Zimbra Collaboration Suite (ZCS) within three days.
The vulnerability, tracked as CVE-2026-73570, was fixed by the Zimbra security team in Zimbra version 10.1.20, released on July 20.
CVE-2026-73570 is a command injection vulnerability in Zimbra’s SNMP monitoring component. If SNMP notifications are enabled, an unauthenticated attacker could exploit the flaw to execute arbitrary operating system commands on a vulnerable server.
According to the vulnerability disclosure, “untrusted input was improperly sanitized during SNMP notification processing,” potentially allowing an unauthenticated attacker to send a specially crafted request and execute arbitrary operating system commands with the privileges of the Zimbra user.
CISA’s warning follows an alert from CERT Polska, Poland’s Computer Emergency Response Team, which reported last Monday that threat actors were actively exploiting the vulnerability in the wild.
Internet scanning data from the Shadowserver Foundation shows more than 12,000 Zimbra servers exposed online. However, it is unclear how many of these systems are honeypots, how many have already been patched, or how many remain vulnerable to attacks exploiting CVE-2026-73570.

On Friday, CISA confirmed CERT Polska’s warning and added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) Catalog. The agency ordered Federal Civilian Executive Branch (FCEB) agencies to secure affected systems by August 24.
Although CISA has not released details about the ongoing attacks, CERT Polska is urging administrators to review their Zimbra logs for signs of compromise. Warning signs may include unexpected Zimbra service restarts and files created by the zimbra user in the following directories during the past 30 days:
/opt/zimbra/jetty/webapps//opt/zimbra/jetty_base/webapps//tmp/
Administrators should update Zimbra Collaboration Suite to a patched release, review systems for suspicious activity, and investigate any indicators of compromise before returning affected servers to normal operation.
Zimbra Collaboration Suite is a widely used email and collaboration platform deployed by organizations and individuals worldwide, including hundreds of government agencies and thousands of businesses.
Zimbra security vulnerabilities are frequently targeted by cybercriminals and state-sponsored threat groups because compromised email servers can provide access to sensitive communications, credentials, and other confidential data.
In March, researchers at Seqrite Labs reported that APT28, a Russia-linked state-sponsored threat group associated with the country’s military intelligence services, exploited a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government Zimbra servers.
In October 2024, U.S. and U.K. cybersecurity agencies warned that APT29, a Russian Foreign Intelligence Service-linked group also tracked as Midnight Blizzard and Cozy Bear, was targeting Zimbra servers by exploiting a vulnerability previously used to steal email account credentials.
Russia-linked cyber espionage group Winter Vivern has also exploited a reflected cross-site scripting (XSS) vulnerability to steal emails from individuals and organizations affiliated with NATO through Zimbra’s webmail portal.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




