CISA Orders Urgent Federal Patching of Actively Exploited Zimbra Collaboration Suite Flaw

The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal civilian agencies to remediate an actively exploited command injection vulnerability in the Zimbra Collaboration Suite within a strict three-day timeframe.

Tracked as CVE-2026-73570, the severe security flaw resides in the SNMP monitoring component of the Zimbra Collaboration Suite. The vulnerability stems from improper input sanitization during the processing of SNMP notifications, allowing unauthenticated attackers to transmit specially crafted SMTP requests that execute arbitrary operating system commands with the privileges of the Zimbra user.

The Zimbra security team originally addressed the vulnerability on July 20, 2026, by rolling out version 10.1.20. However, urgency escalated after CERT Polska flagged active exploitation in the wild, prompting CISA to add the vulnerability to its Known Exploited Vulnerabilities catalog on August 21, 2026, and mandate remediation for U.S. Federal Civilian Executive Branch agencies by August 24, 2026.

Internet telemetry collected by threat intelligence watchdog Shadowserver revealed more than 12,000 Zimbra instances publicly exposed online, alongside over 270 compromised enterprise and organization servers exhibiting artifacts linked to CVE-2026-73570 exploitation. Security researchers recommend that administrators audit system logs for unexpected service restarts and investigate unauthorized file creation in directories such as /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.

State-sponsored actor groups have frequently targeted Zimbra Collaboration Suite deployments to breach government agencies, military networks, and international organizations. Recent campaigns include intrusions by Russian military intelligence operatives associated with APT28 and Foreign Intelligence Service-linked groups like APT29 targeting high-profile email and webmail environments.

CISA explained in its advisory: Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Leave a Reply

Your email address will not be published. Required fields are marked *