Updated
Updated · BleepingComputer · Aug 24
CISA Orders 3-Day Patch for Actively Exploited Zimbra RCE Flaw
Updated
Updated · BleepingComputer · Aug 24

CISA Orders 3-Day Patch for Actively Exploited Zimbra RCE Flaw

3 articles · Updated · BleepingComputer · Aug 24

Summary

  • U.S. federal civilian agencies were told to secure Zimbra Collaboration Suite by Aug. 24 after CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog.
  • Zimbra fixed the bug in version 10.1.20 on July 20; the flaw lets unauthenticated attackers execute OS commands through command injection in the SNMP monitoring component when notifications are enabled.
  • CERT Polska first reported in-the-wild targeting last week, and Shadowserver said Monday it found more than 270 compromised Zimbra instances while tracking exploitation artifacts.
  • Shadowserver also sees more than 12,000 internet-exposed Zimbra servers, though it is unclear how many are honeypots or already patched.
  • Zimbra has repeatedly drawn state-linked attacks, including campaigns tied to APT28, APT29 and Winter Vivern against government and NATO-aligned targets.

Insights

With today's CISA deadline here, how many of the 12,000 exposed Zimbra servers are already silently harboring state-sponsored attackers?
Following 2025's massive breaches, which unknown threat actor is currently weaponizing this new Zimbra flaw to steal sensitive email data?
Why did an optional SNMP monitoring component become the ultimate backdoor for a massive, actively exploited cyberattack on government servers?