Zimbra CVE-2026-73570 Zero-Day Added to CISA KEV Under Active Exploitation
Key findings • Zimbra CVE-2026-73570 confirmed actively exploited in the wild. • CISA added this critical vulnerability to its KEV catalog on August 21, 2026. • Organizations using Zimbra…

Key findings
- Zimbra CVE-2026-73570 confirmed actively exploited in the wild.
- CISA added this critical vulnerability to its KEV catalog on August 21, 2026.
- Organizations using Zimbra must prioritize immediate patching to mitigate severe risks.
CISA has issued a critical alert regarding a newly identified Zimbra vulnerability, CVE-2026-73570, which has been added to its Known Exploited Vulnerabilities (KEV) catalog on August 21, 2026. This inclusion signifies that the flaw is under active exploitation in real-world attacks, posing an immediate and severe risk to organizations utilizing Zimbra products. The KEV catalog serves as a definitive list of vulnerabilities that federal civilian executive branch (FCEB) agencies are required to remediate within specific deadlines, underscoring the urgency for all organizations to address this threat.
The vulnerability, identified as CVE-2026-73570, represents a significant security bypass or remote code execution flaw within Zimbra's widely used collaboration suite. While specific technical details of the exploit are often withheld by CISA to prevent further weaponization, its presence in the KEV catalog confirms that threat actors are successfully leveraging this weakness to compromise systems. Organizations running vulnerable versions of Zimbra are therefore at heightened risk of unauthorized access, data breaches, and system disruption.
At present, there is no public information linking CVE-2026-73570 directly to ransomware campaigns. However, actively exploited vulnerabilities are frequently adopted by various threat actors, including those involved in ransomware, as initial access vectors. The absence of a direct ransomware tag does not diminish the critical need for immediate remediation.
Defenders must prioritize the immediate patching of all affected Zimbra installations. CISA's directive for FCEB agencies mandates remediation of KEV entries, and while specific due dates for this particular CVE are not yet public, the general guidance for actively exploited flaws is to patch as soon as possible, often within days or weeks. Organizations should consult official Zimbra advisories for patches and mitigation strategies, implement robust monitoring for signs of compromise, and review their incident response plans. Proactive patching and diligent security practices are essential to protect against the ongoing threat posed by this actively exploited vulnerability.