Tag: Email Security

  • CISA Deadline Passes for Federal Agencies to Patch Actively Exploited Zimbra Flaw

    CISA Deadline Passes for Federal Agencies to Patch Actively Exploited Zimbra Flaw

    August 24, 2026, was the deadline for US federal civilian executive branch agencies to mitigate or discontinue use of Zimbra Collaboration Suite (ZCS) systems affected by CVE-2026-73570, a critical, actively exploited remote-code-execution flaw, after the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog on August 21, according to reporting from Dark Reading and The Hacker News.

    Background on the flaw

    Zimbra disclosed CVE-2026-73570, a command-injection vulnerability in the optional zimbra-snmp component that can allow unauthenticated remote code execution when SNMP notifications are enabled, and released a patched version, ZCS 10.1.20, on July 20, 2026. Poland’s CERT Polska warned on August 16–17 that the flaw was being actively exploited in the wild, and BleepingComputer reported on the active exploitation campaign on August 20. CISA added the vulnerability to its KEV catalog on August 21 and required federal civilian agencies to remediate by August 24.

    Why it matters

    Zimbra Collaboration Suite is widely used email and collaboration software across businesses and government agencies. An unauthenticated remote-code-execution flaw in internet-facing collaboration infrastructure, already confirmed as being actively exploited before a patch was applied everywhere, is exactly the scenario CISA’s KEV deadlines are designed to force organizations to act on quickly. Security teams running Zimbra Collaboration Suite that have not yet applied version 10.1.20 or later, or disabled the affected SNMP component, should treat this as an active, ongoing exploitation risk rather than a theoretical one.

    Sources

    More coverage like this is available on Technology News.