CISA orders urgent patching of actively exploited Zimbra flaw
Reported exploitedZimbra Collaboration SuiteOur summary
CISA has directed U.S. federal agencies to patch a critical vulnerability in Zimbra Collaboration Suite within three days due to active exploitation in the wild. Tracked as CVE-2026-73570, this command injection flaw in the SNMP monitoring component allows unauthenticated attackers to achieve remote code execution if SNMP notifications are enabled. Zimbra addressed the issue in version 10.1.20, and security teams should update immediately while monitoring for suspicious file creation or service restarts.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.