CISA's Three-Day Zimbra Patch Deadline Expires as Exploitation Spreads
Want more insights like this?
CISA gave federal agencies until 24 August 2026 to patch CVE-2026-73570, a Zimbra flaw allowing unauthenticated remote code execution through crafted SMTP requests. That deadline has now expired. The CVE record scores it 8.9 (High); Zimbra and CERT Polska both describe it as critical.
The flaw only bites where three things line up: the optional zimbra-snmp package is installed, SNMP notifications are enabled via snmp_notify, and the swatchdog service is running. Only the last of those is on by default. Zimbra shipped the permanent fix in ZCS 10.1.20 on 20 July, and every earlier version is affected.
Exploitation was confirmed on 17 August, when Poland's CERT Polska flagged an ongoing campaign. CISA added the flaw to its KEV catalog on 21 August and gave three days, under the tiered model it adopted in June citing AI-accelerated exploit development. Shadowserver counted 155 compromised internet-facing instances on 20 August and 274 by the 22nd, plus roughly 8,200 unpatched.
Patching closes the entry point but does not remove persistence installed before it, Sectigo's Jason Soroko notes. CERT Polska says to check /var/log/zimbra.log for unexpected "Service status change" entries, and anything the zimbra user created in the last 30 days under the Jetty webapps directories or /tmp. Treat an exposed server as an incident, not a patch.
Source: Dark Reading