CISA Orders Federal Agencies to Patch Zimbra Command Injection Flaw by August 24
CISA added CVE-2026-73570, an actively exploited OS command-injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities catalog on August 21, giving Federal Civilian Executive Branch agencies three days to remediate. The flaw, scored CVSS 8.9, allows unauthenticated attackers to execute arbitrary commands via crafted SMTP requests on systems running the optional zimbra-snmp package with SNMP notifications enabled. A patch has been available since July 20 in Zimbra version 10.1.20; no threat actor or victim count has been publicly confirmed.