0%
Skip to content
24 August 2026
LanguageEnglish
System

Appearance

Breaking News

CISA Orders Urgent Patching for Actively Exploited Zimbra Collaboration Suite Flaw

CISA orders federal agencies to patch an actively exploited remote code execution flaw in Zimbra Collaboration Suite within three days.

3 min read
Zimbra flaw, Zimbra Collaboration Suite, CVE-2026-73570, CISA directive, remote code execution, Zimbra security update

CISA Directive and Vulnerability Details

The Cybersecurity and Infrastructure Security Agency (CISA) has formally ordered U.S. Federal Civilian Executive Branch agencies to secure their systems against an actively exploited security vulnerability affecting the Zimbra Collaboration Suite (ZCS). Tracked as CVE-2026-73570, the security flaw was patched by the Zimbra security team in version 10.1.20, which was released on July 20. The issue originates within the SNMP monitoring component of the collaboration software.

Successful exploitation of this weakness allows unauthenticated attackers to achieve remote code execution on targeted systems. The vulnerability specifically arises when SNMP notifications are enabled on the targeted system, due to improper sanitization of untrusted input during SNMP notification processing. By sending specially crafted Simple Mail Transfer Protocol (SMTP) requests, an unauthenticated attacker can cause the execution of arbitrary operating system commands as the Zimbra user.

The Zimbra security team previously released a software update addressing this security flaw in version 10.1.20 on July 20. However, subsequent real-world observations confirmed that the vulnerability is actively targeted by malicious actors in ongoing campaigns.

Discovery and Real-World Exploitation

CISA’s warning comes after CERT Polska, the Polish Computer Emergency Response Team, first flagged the vulnerability as targeted in the wild last Monday. On Friday, CISA confirmed CERT Polska’s alert, added the flaw to its Known Exploited Vulnerabilities catalog, and ordered U.S. Federal Civilian Executive Branch agencies to secure their systems within three days, by August 24.

Independent security organizations and threat watchdogs have monitored the widespread exposure and potential compromise of servers running the software. While threat security watchdog Shadowserver tracks more than 12,000 Zimbra servers exposed on the Internet, there is no information on how many are honeypots or have already been secured against attacks exploiting the CVE-2026-73570 flaw.

You Might Also Like:  Calgary Zoo Investigates Grizzly Bear Escape Incident

On Monday, Shadowserver also said it has found over 270 compromised Zimbra Collaboration Suite instances while looking for CVE-2026-73570 exploitation artifacts. Although CISA didn’t share any information on these ongoing attacks, the Polish CERT team asked security teams to check logs for suspicious activity, such as the Zimbra service restarting unexpectedly, and for files created in specific locations.

  • Check for suspicious activity such as the Zimbra service restarting unexpectedly.
  • Look for files created in the /opt/zimbra/jetty/webapps/ folder by user zimbra over the last 30 days.
  • Inspect the /opt/zimbra/jetty_base/webapps/ folder for files created by user zimbra over the last 30 days.
  • Examine the /tmp/ folder for files created by user zimbra over the last 30 days.

Context and Prior Targeting of Zimbra Software

ZCS is a popular email and collaboration suite used by hundreds of millions of organizations and people worldwide, including hundreds of government agencies and thousands of businesses. Zimbra security issues are commonly targeted in the wild and have been used to steal sensitive data from vulnerable email servers in recent years.

Most recently, Seqrite Labs researchers revealed in March that APT28, a state-sponsored threat group linked to Russia’s military intelligence service, was exploiting a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers. In October 2024, U.S. and UK cyber agencies warned that APT29 hackers, tracked as Midnight Blizzard and Cozy Bear and linked to Russia’s Foreign Intelligence Service, were targeting Zimbra servers using a flaw previously exploited to steal email account credentials. Russian Winter Vivern cyber spies have also abused a reflected Cross-Site Scripting (XSS) vulnerability to steal emails belonging to NATO-aligned individuals and organizations via Zimbra webmail portals.

You Might Also Like:  Bali Gym Denies Entry to Israeli Tourists Over Military Links

What happens next

U.S. Federal Civilian Executive Branch agencies are required to complete patching or mitigation of the CVE-2026-73570 vulnerability in accordance with CISA’s mandated three-day deadline by August 24.

Source: Original Article

Portrait of Tayfur Keleş

Editorial responsibility

Tayfur Keleş

Founder & Responsible Editor

Digital content creator and entrepreneur focused on global media platforms, multi-language publishing, and modern web technologies.