CISA Mandates Urgent Patch for Actively Exploited Zimbra RCE Flaw
The Cybersecurity and Infrastructure Security Agency (**CISA**) has issued a directive for U.S. government agencies to immediately patch a critical, actively exploited vulnerability in **Zimbra Collaboration Suite** (**ZCS**). Tracked as **CVE-2026-73570**, this flaw allows unauthenticated attackers to achieve remote code execution, posing a significant threat to organizations relying on the popular email and collaboration platform.
The **Zimbra Collaboration Suite** (**ZCS**), a widely used email and collaboration platform, is once again at the center of a critical security alert. The Cybersecurity and Infrastructure Security Agency (**CISA**) has ordered U.S. federal agencies to patch an actively exploited vulnerability within a tight three-day deadline.
### Critical RCE Flaw Under Active Exploitation
The vulnerability, identified as **CVE-2026-73570**, is a command injection weakness found in the **ZCS** SNMP monitoring component. When SNMP notifications are enabled, this flaw can be exploited by unauthenticated attackers to achieve remote code execution. **Zimbra**'s security team addressed the issue in **version 10.1.20**, released on July 20.
According to **Zimbra**, "Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user."
### CISA's Urgent Directive and Threat Landscape
**CISA**'s mandate follows an initial alert from **CERT Polska**, the Polish Computer Emergency Response Team, which first flagged the vulnerability as being actively exploited in the wild. On August 21, **CISA** officially added **CVE-2026-73570** to its Known Exploited Vulnerabilities (**KEV**) catalog, compelling U.S. Federal Civilian Executive Branch (**FCEB**) agencies to apply the patch by August 24.
Cybersecurity watchdog **Shadowserver** reports over 12,000 **Zimbra** servers exposed to the internet. More concerningly, **Shadowserver** has already identified over 270 compromised **Zimbra Collaboration Suite** instances exhibiting exploitation artifacts related to **CVE-2026-73570**.

While **CISA** has not disclosed details of ongoing attacks, **CERT Polska** advises security teams to scrutinize logs for unusual activity, such as unexpected **Zimbra** service restarts or the creation of suspicious files in `/opt/zimbra/jetty/webapps/`, `/opt/zimbra/jetty_base/webapps/`, and `/tmp/` folders by the `zimbra` user within the last 30 days.
### A Recurring Target for Sophisticated Threat Actors
**ZCS** is a ubiquitous platform, serving hundreds of millions of users globally, including numerous government bodies and businesses. Unfortunately, **Zimbra** security vulnerabilities are frequently targeted by threat actors, often leading to the theft of sensitive data from vulnerable email servers.
Recent incidents highlight this trend:
* In March, researchers revealed that **APT28** (a state-sponsored group linked to Russia's military intelligence) exploited a stored cross-site scripting (**XSS**) vulnerability in attacks against Ukrainian government **ZCS** servers.
* In October 2024, U.S. and UK cyber agencies warned that **APT29** (also known as **Midnight Blizzard** or **Cozy Bear**), tied to Russia's Foreign Intelligence Service, was targeting **Zimbra** servers using a flaw previously exploited to steal email account credentials.
* Russian cyber espionage group **Winter Vivern** has also leveraged a reflected **XSS** vulnerability to compromise **Zimbra** webmail portals, stealing emails from individuals and organizations aligned with NATO.