logo

CISA orders urgent patching of actively exploited Zimbra flaw

ID: 77ad472f-b3fc-54dd-848b-0f111ade9138

STIX ID: report--77ad472f-b3fc-54dd-848b-0f111ade9138

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Sergiu Gatlan

...
...

CISA has ordered U.S. federal agencies to patch CVE-2026-73570 — an unauthenticated command-injection vulnerability in Zimbra Collaboration Suite's SNMP notification component that allows remote code execution — following CERT Polska reports of active exploitation; Zimbra released a fix in 10.1.20 (July 20), Shadowserver reports over 12,000 exposed servers, and guidance includes checking for unexpected Zimbra restarts and files created by the zimbra user in specific webapp and tmp directories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.