Skip to content
See the World Through Science

CISA Gave Federal Agencies Three Days to Patch an Exploited Zimbra Flaw

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Rows of rack-mounted server units stacked floor to ceiling in a data centre aisle, each unit trailing pale network and power cables.
Rack-mounted servers in a data centre. Illustrative: this is not an affected system. CISA's deadline applied to federal civilian agencies running Zimbra Collaboration Suite, and the agency publishes no inventory of which machines those are."Server room" by torkildr, via flickr, CC-BY-SA-2.0 · CC-BY-SA-2.0

A three-day deadline for U.S. federal civilian agencies to fix a flaw in Zimbra's email and collaboration software fell due on Aug. 24. The Cybersecurity and Infrastructure Security Agency added the flaw, CVE-2026-73570, to its Known Exploited Vulnerabilities catalog on Aug. 21 with that date attached.

The catalog entry names the affected product as Synacor's Zimbra Collaboration Suite and classifies the flaw as an operating-system command injection weakness, CWE-78. CISA's description says an unauthenticated attacker could use it to run arbitrary operating system commands as the Zimbra user. The entry's field for whether the flaw is known to be used in ransomware campaigns reads "Unknown."

The catalog is CISA's list of vulnerabilities it says have been exploited in the wild. Each entry carries a due date under Binding Operational Directive 26-04, which the agency issued to replace the 2021 directive that created the catalog. The directive binds what CISA calls Federal Civilian Executive Branch agencies, and this entry instructs them to apply the vendor's mitigations and to carry out a forensic triage of the affected systems, or to stop using the product if no mitigation is available.

CISA's entry points to Zimbra's own patch note of July 20, which announced version 10.1.20 of the suite. Zimbra describes that release as carrying a permanent fix for a command injection flaw in the software's SNMP monitoring component, disclosed in an advisory on June 26. Zimbra's note names no CVE identifier, and its account of where the flaw sits differs from CISA's, which places it in the handling of specially crafted SMTP requests.

The directive's deadlines bind federal agencies only. CISA publishes the catalog for all network defenders and says organizations should use it as an input to their own patching priorities.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

CISA Gave Federal Agencies Three Days to Patch an Exploited Zimbra Flaw

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.