U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
ID: e0c3af75-87d6-51be-9f3e-c8c2f1270527
STIX ID: report--e0c3af75-87d6-51be-9f3e-c8c2f1270527
Feed Name: Security Affairs
CISA added a critical Zimbra Collaboration Suite flaw (CVE-2026-73570) to its Known Exploited Vulnerabilities catalog after CERT Polska confirmed active exploitation. The vulnerability allows unauthenticated remote code execution when the optional zimbra-snmp package has SNMP notifications enabled and the swatchdog service is running; Zimbra released version 10.1.20 to patch the issue and CISA ordered federal agencies to remediate by August 24, 2026. CERT Polska published indicators and recommended checking zimbra logs and files created by the zimbra user for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
