CISA Gave Federal Agencies Three Days to Patch an Exploited Zimbra Flaw

A three-day deadline for U.S. federal civilian agencies to fix a flaw in Zimbra's email and collaboration software fell due on Aug. 24. The Cybersecurity and Infrastructure Security Agency added the flaw, CVE-2026-73570, to its Known Exploited Vulnerabilities catalog on Aug. 21 with that date attached.
The catalog entry names the affected product as Synacor's Zimbra Collaboration Suite and classifies the flaw as an operating-system command injection weakness, CWE-78. CISA's description says an unauthenticated attacker could use it to run arbitrary operating system commands as the Zimbra user. The entry's field for whether the flaw is known to be used in ransomware campaigns reads "Unknown."
The catalog is CISA's list of vulnerabilities it says have been exploited in the wild. Each entry carries a due date under Binding Operational Directive 26-04, which the agency issued to replace the 2021 directive that created the catalog. The directive binds what CISA calls Federal Civilian Executive Branch agencies, and this entry instructs them to apply the vendor's mitigations and to carry out a forensic triage of the affected systems, or to stop using the product if no mitigation is available.
CISA's entry points to Zimbra's own patch note of July 20, which announced version 10.1.20 of the suite. Zimbra describes that release as carrying a permanent fix for a command injection flaw in the software's SNMP monitoring component, disclosed in an advisory on June 26. Zimbra's note names no CVE identifier, and its account of where the flaw sits differs from CISA's, which places it in the handling of specially crafted SMTP requests.
The directive's deadlines bind federal agencies only. CISA publishes the catalog for all network defenders and says organizations should use it as an input to their own patching priorities.
