VYPR
Published Aug 21, 2026· Updated Aug 26, 2026· 4 sources

Zimbra CVE-2026-73570 Zero-Day Added to CISA KEV Under Active Exploitation

Key findings • Zimbra CVE-2026-73570 confirmed actively exploited in the wild. • CISA added this critical vulnerability to its KEV catalog on August 21, 2026. • Organizations using Zimbra…

Key findings

  • Zimbra CVE-2026-73570 confirmed actively exploited in the wild.
  • CISA added this critical vulnerability to its KEV catalog on August 21, 2026.
  • Organizations using Zimbra must prioritize immediate patching to mitigate severe risks.

CISA has issued a critical alert regarding a newly identified Zimbra vulnerability, CVE-2026-73570, which has been added to its Known Exploited Vulnerabilities (KEV) catalog on August 21, 2026. This inclusion signifies that the flaw is under active exploitation in real-world attacks, posing an immediate and severe risk to organizations utilizing Zimbra products. The KEV catalog serves as a definitive list of vulnerabilities that federal civilian executive branch (FCEB) agencies are required to remediate within specific deadlines, underscoring the urgency for all organizations to address this threat.

The vulnerability, identified as CVE-2026-73570, represents a significant security bypass or remote code execution flaw within Zimbra's widely used collaboration suite. While specific technical details of the exploit are often withheld by CISA to prevent further weaponization, its presence in the KEV catalog confirms that threat actors are successfully leveraging this weakness to compromise systems. Organizations running vulnerable versions of Zimbra are therefore at heightened risk of unauthorized access, data breaches, and system disruption.

At present, there is no public information linking CVE-2026-73570 directly to ransomware campaigns. However, actively exploited vulnerabilities are frequently adopted by various threat actors, including those involved in ransomware, as initial access vectors. The absence of a direct ransomware tag does not diminish the critical need for immediate remediation.

Defenders must prioritize the immediate patching of all affected Zimbra installations. CISA's directive for FCEB agencies mandates remediation of KEV entries, and while specific due dates for this particular CVE are not yet public, the general guidance for actively exploited flaws is to patch as soon as possible, often within days or weeks. Organizations should consult official Zimbra advisories for patches and mitigation strategies, implement robust monitoring for signs of compromise, and review their incident response plans. Proactive patching and diligent security practices are essential to protect against the ongoing threat posed by this actively exploited vulnerability.

CERT Polska has issued a specific warning detailing the active exploitation of CVE-2026-73570, a critical OS command-injection flaw in Zimbra Collaboration Suite. The vulnerability allows remote, unauthenticated attackers to execute arbitrary shell commands as the zimbra user, particularly when the SNMP trap service is enabled and swatchdog is running. Successful exploitation can lead to data theft, web shell deployment, and further compromise of internal systems.

CISA has issued an emergency directive mandating federal agencies patch Zimbra vulnerability CVE-2026-73570 within a strict three-day window. This directive underscores the critical nature of the flaw, which allows for a full takeover of a user's email and communication systems, posing a significant risk to sensitive data and ongoing operations.

The exploitation of Zimbra Collaboration Suite, tracked as CVE-2026-73570, has escalated with at least 267 instances confirmed compromised globally. Recent data indicates that over 8,000 Zimbra servers remain unpatched and vulnerable to unauthenticated remote code execution, a significant increase from previous reports. The vulnerability, which allows attackers to access sensitive mail data and system resources, was added to CISA's Known Exploited Vulnerabilities catalog on August 21, 2026, following its initial disclosure by Zimbra on June 26 and the release of a fix on July 20.

Synthesized by Vypr AI
Zimbra CVE-2026-73570 Zero-Day Added to CISA KEV Under Active Exploitation · VYPR