CISA added a Zimbra vulnerability, CVE-2026-73570 (CVSS 8.9, High), to its Known Exploited Vulnerabilities catalog on August 21, giving federal civilian agencies until August 24 to patch or stop using the software — a deadline that has now passed. The fix is Zimbra Collaboration Suite 10.1.20, released July 20.
The flaw lets unauthenticated attackers run arbitrary OS commands as the Zimbra user through crafted SMTP requests. Exposure is narrower than it sounds — only servers with the optional zimbra-snmp package installed and SNMP notifications enabled are affected. CERT Polska flagged an active campaign hunting them on August 16.
Merlin Group's Robert Costello notes that compromising a Zimbra server exposes messages, calendars, contacts and attachments, along with internal naming conventions and maintenance schedules — enough to fuel follow-on attacks. Patching won't evict an intruder already inside, so exposed servers need checking against CERT Polska's indicators, not just updating.
Black Hills Information Security's John Strand argues AI is compressing the gap between disclosure and working exploit, pushing urgent patching closer to incident response than routine maintenance.
Source: Dark Reading