Updated
Updated · The Hacker News · Aug 22
CISA Adds Zimbra RCE Flaw CVE-2026-73570 to KEV, Orders Fixes by Aug. 24
Updated
Updated · The Hacker News · Aug 22

CISA Adds Zimbra RCE Flaw CVE-2026-73570 to KEV, Orders Fixes by Aug. 24

3 articles · Updated · The Hacker News · Aug 22

Summary

  • Aug. 21, CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog after reports of active attacks, giving federal civilian agencies until Aug. 24 to patch.
  • The flaw carries a CVSS score of 8.9 and affects Zimbra Collaboration before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
  • Improper input sanitization in SNMP notification processing lets unauthenticated attackers send crafted SMTP requests that execute arbitrary operating system commands as the Zimbra user.
  • CERT Polska said exploitation is already underway and urged administrators to inspect /var/log/zimbra.log for suspicious service restarts and recent files in webapps and /tmp directories.
  • Zimbra patched the issue last month in version 10.1.20, adding to pressure on users of a platform that has repeatedly drawn threat actors, including in a separate Russia-linked campaign disclosed last month.

Insights

With hackers actively exploiting Zimbra's latest flaw, what hidden artifacts might already be lurking inside your unpatched email server?
Why are advanced threat actors continuously targeting Zimbra platforms, and could this unique attack vector signal a deeper architectural crisis?