← Back to overview

CISA has issued an emergency directive ordering U.S. federal agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The flaw is being actively exploited in the wild, prompting the urgent response from CISA. Zimbra Collaboration Suite is widely used by government and enterprise organizations for email and collaboration. The directive reflects CISA's Known Exploited Vulnerabilities (KEV) catalog process, which mandates timely remediation for confirmed exploited flaws. The short three-day patching window indicates the severity and active exploitation of the vulnerability. Organizations using ZCS are urged to apply available patches immediately to reduce risk of compromise.

Technical details

CVE-2026-73570 is a command injection vulnerability in the SNMP monitoring component of Zimbra Collaboration Suite (ZCS). The flaw arises from improper sanitization of untrusted input during SNMP notification processing. An unauthenticated remote attacker can send specially crafted SMTP requests that result in execution of arbitrary operating system commands as the Zimbra user. Exploitation requires SNMP notifications to be enabled on the targeted system. The vulnerability enables full unauthenticated remote code execution (RCE). CERT Polska first flagged active exploitation in the wild. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on August 21, 2026, and mandated Federal Civilian Executive Branch (FCEB) agencies to remediate by August 24, 2026. Over 12,000 Zimbra servers are tracked as internet-exposed by Shadowserver.

Mitigation steps

1. Immediately upgrade Zimbra Collaboration Suite to version 10.1.20 or later, released July 20, 2026. 2. U.S. FCEB agencies must remediate by August 24, 2026 per CISA mandate. 3. Check system logs for signs of exploitation, including unexpected Zimbra service restarts. 4. Review files created by the 'zimbra' user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ directories over the last 30 days. 5. If SNMP notifications are not required, consider disabling them to reduce attack surface. 6. Monitor for suspicious or specially crafted SMTP requests targeting the SNMP notification processing component.

Affected products

  • Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20

Related CVE's

  • CVE-2026-73570

Related threat actors

  • APT28 (linked to Russia's military intelligence service
  • APT29 (Midnight Blizzard / Cozy Bear
  • GRU)
  • SVR)
  • Winter Vivern
  • linked to Russia's Foreign Intelligence Service

IOC's

Unexpected restart of the Zimbra service, Files created in /opt/zimbra/jetty/webapps/ by user zimbra within the last 30 days, Files created in /opt/zimbra/jetty_base/webapps/ by user zimbra within the last 30 days, Files created in /tmp/ by user zimbra within the last 30 days, Suspicious SMTP requests targeting the SNMP notification processing component

Categories

  • Email & Messaging
  • Enterprise Applications
  • Zero-Day Vulnerabilities

Related links