The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The deadline for Federal Civilian Executive Branch (FCEB) agencies to secure their systems was set for August 24.
The vulnerability, identified as CVE-2026-73570, is a command injection weakness found in the SNMP monitoring component of ZCS. It allows unauthenticated attackers to achieve remote code execution if SNMP notifications are enabled on the target system. The flaw stems from insufficient sanitization of untrusted input during the processing of SNMP notifications, enabling attackers to send specially crafted SMTP requests that can execute arbitrary operating system commands under the privileges of the Zimbra user.
Zimbra's security team addressed this flaw in version 10.1.20, which was released on July 20. CISA's directive follows an alert from CERT Polska, the Polish Computer Emergency Response Team, which first reported active exploitation of the vulnerability last Monday. CISA confirmed CERT Polska's findings and subsequently added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog.
While CISA has not disclosed specific details regarding the ongoing attacks, CERT Polska has advised security teams to examine logs for unusual activities. These include unexpected restarts of the Zimbra service and the presence of files created by the 'zimbra' user in the `/opt/zimbra/jetty/webapps/`, `/opt/zimbra/jetty_base/webapps/`, and `/tmp/` directories over the past 30 days.
ZCS is a widely used email and collaboration platform, serving numerous organizations and individuals globally, including government entities and businesses. Zimbra security vulnerabilities have frequently been targeted in the past, leading to data theft from vulnerable email servers.
Previous incidents include exploitation by APT28, a state-sponsored threat group, which utilized a stored cross-site scripting (XSS) vulnerability in attacks against Ukrainian government ZCS servers, as reported in March. In October 2024, U.S. and UK cyber agencies issued warnings about APT29, also known as Midnight Blizzard or Cozy Bear, targeting Zimbra servers with a flaw previously used to steal email account credentials. Additionally, the Russian cyber espionage group Winter Vivern has exploited a reflected Cross-Site Scripting (XSS) vulnerability to compromise emails of individuals and organizations aligned with NATO via Zimbra webmail portals.
Shadowserver, a threat security watchdog, currently tracks over 12,000 Zimbra servers exposed on the internet, though it is unclear how many of these are honeypots or have already been patched against CVE-2026-73570.






