CVE-2026-73570 is a critical unauthenticated RCE in Zimbra Collaboration Suite being exploited right now. CISA added it to its Known Exploited Vulnerabilities catalog on August 21 and ordered federal agencies to patch by August 24.
Read the full story: Zimbra RCE Flaw Under Active Attack, CISA Gives Feds 3 Days →
Transcript
A Zimbra mail server doesn't need a stolen password to get taken over right now. CVE-2026-73570 is an unauthenticated remote code execution flaw, and CERT Polska caught it being exploited in the wild on August nineteenth. The fix shipped a month earlier, on July twentieth, quietly, no big advisory. Two days after exploitation surfaced, CISA added it to the Known Exploited Vulnerabilities catalog and gave federal agencies three days to patch. That deadline already passed. Shadowserver has counted over two hundred seventy compromised servers, out of more than twelve thousand exposed to the open internet. If you run Zimbra with SNMP notifications on, patch to version ten one twenty right now.