<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

CISA Gave Federal Agencies Three Days to Patch Actively Exploited Zimbra Flaw

Attackers were already exploiting a Zimbra flaw before CISA's deadline. Only servers with the optional SNMP package are exposed; ZCS 10.1.20 fixes it.
Content Team

CISA added a Zimbra vulnerability, CVE-2026-73570 (CVSS 8.9, High), to its Known Exploited Vulnerabilities catalog on August 21, giving federal civilian agencies until August 24 to patch or stop using the software — a deadline that has now passed. The fix is Zimbra Collaboration Suite 10.1.20, released July 20.

The flaw lets unauthenticated attackers run arbitrary OS commands as the Zimbra user through crafted SMTP requests. Exposure is narrower than it sounds — only servers with the optional zimbra-snmp package installed and SNMP notifications enabled are affected. CERT Polska flagged an active campaign hunting them on August 16.

Merlin Group's Robert Costello notes that compromising a Zimbra server exposes messages, calendars, contacts and attachments, along with internal naming conventions and maintenance schedules — enough to fuel follow-on attacks. Patching won't evict an intruder already inside, so exposed servers need checking against CERT Polska's indicators, not just updating.

Black Hills Information Security's John Strand argues AI is compressing the gap between disclosure and working exploit, pushing urgent patching closer to incident response than routine maintenance.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo