CISA mandates three-day patch for exploited Zimbra vulnerability
CISA has ordered U.S. federal agencies to patch CVE-2026-73570, an actively exploited command injection flaw in Zimbra Collaboration Suite's SNMP component, within three days. The vulnerability allows unauthenticated remote code execution and was patched in version 10.1.20. CERT Polska first flagged in-the-wild attacks, and Shadowserver found over 270 compromised Zimbra instances.
The vulnerability stems from improper input sanitization in Zimbra's SNMP notification processing, enabling unauthenticated attackers to execute arbitrary operating system commands as the Zimbra user via crafted SMTP requests. The flaw was patched in version 10.1.20, released July 20, with CERT Polska first flagging in-the-wild attacks the following Monday. Shadowserver identified over 270 compromised instances while scanning for exploitation artifacts, though more than 12,000 Zimbra servers remain internet-exposed.
Zimbra has a documented history of being targeted by state-sponsored actors. APT28 exploited a stored XSS vulnerability against Ukrainian government servers in March, while APT29 and Winter Vivern have previously leveraged Zimbra flaws to steal email credentials and intercept communications from NATO-aligned targets. The current CISA directive requires Federal Civilian Executive Branch agencies to remediate within three days, by August 24.
This directive highlights how quickly critical infrastructure and government communications can be compromised through widely deployed software. Organizations relying on Zimbra—including government agencies, businesses, and institutions worldwide—may face data breaches, credential theft, and operational disruption if unpatched. The involvement of state-sponsored groups in prior Zimbra attacks suggests this vulnerability could be exploited for espionage purposes, potentially affecting national security and diplomatic communications. Smaller organizations without dedicated security teams may be particularly vulnerable, as three-day patch mandates may exceed their operational capacity.