CISA orders urgent patching of actively exploited Zimbra flaw
ID: 77ad472f-b3fc-54dd-848b-0f111ade9138
STIX ID: report--77ad472f-b3fc-54dd-848b-0f111ade9138
Feed Name: Bleeping Computer
CISA has ordered U.S. federal agencies to patch CVE-2026-73570 — an unauthenticated command-injection vulnerability in Zimbra Collaboration Suite's SNMP notification component that allows remote code execution — following CERT Polska reports of active exploitation; Zimbra released a fix in 10.1.20 (July 20), Shadowserver reports over 12,000 exposed servers, and guidance includes checking for unexpected Zimbra restarts and files created by the zimbra user in specific webapp and tmp directories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
