Cybersecurity

CISA Gives U.S. Agencies Three Days to Patch an Exploited Zimbra Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency ordered federal civilian agencies to secure Zimbra servers within three days against an actively exploited remote code execution vulnerability. Shadowserver data indicates that more than 270 compromised instances have been observed, while the number of Zimbra servers exposed to the internet exceeds 12,000.

2026-08-24
4 min read
13 views
فريق تحرير certi.news
CISA Gives U.S. Agencies Three Days to Patch an Exploited Zimbra Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered civilian agencies of the U.S. federal executive branch to update Zimbra Collaboration Suite (ZCS) systems within three days, after confirming that a security vulnerability had been exploited in real-world attacks and adding it to the Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability, tracked as CVE-2026-73570, allows an unauthenticated attacker to execute commands remotely through a command injection flaw in the SNMP monitoring component when SNMP notifications are enabled on the targeted server. According to the Zimbra team, the issue results from the failure to sanitize untrusted input while processing SNMP notifications, enabling specially crafted SMTP requests that may lead to operating system command execution with zimbra user privileges.

The Release That Addresses the Issue

The Zimbra team fixed the flaw in version 10.1.20, released on July 20. Thus, the required action is not limited to monitoring suspicious activity; organizations still running an affected version are required to move to the patched version under their urgent security schedule, prioritizing servers exposed to the internet.

CISA's action followed a warning from the Polish Computer Emergency Response Team, CERT Polska, that the vulnerability was being targeted in the wild. On Monday, Shadowserver said it had detected more than 270 compromised Zimbra instances while searching for signs of CVE-2026-73570 exploitation, while it was tracking more than 12,000 Zimbra servers exposed to the internet. The available data does not clarify how many of these servers are honeypots or have already been secured.

What Should Be Checked in Practice?

CISA has not published details about the ongoing attacks, but CERT Polska asked security teams to review logs for indicators, including an unexpected restart of the Zimbra service or the creation of files within the last 30 days in the following paths by the zimbra user:

  • /opt/zimbra/jetty/webapps/
  • /opt/zimbra/jetty_base/webapps/
  • /tmp/

Why Does This News Matter?

The vulnerability's significance stems from the combination of three factors: no authentication is required, commands can be executed on the server, and exploitation is occurring in the wild. The risk is more immediate for organizations that use ZCS for email and collaboration and expose its interfaces or components to the internet, because compromising a mail server may give an attacker access to correspondence and sensitive data, depending on the level of privileges and the controls surrounding the system.

The warning also fits a recurring pattern of Zimbra targeting. Researchers at Seqrite Labs reported in March that the APT28 group had exploited a stored XSS vulnerability against Ukrainian government ZCS servers, while U.S. and British authorities warned in October 2024 that APT29 was targeting Zimbra servers with a flaw previously used to steal email credentials. A reflected XSS vulnerability had also previously been used to steal messages belonging to individuals and organizations associated with the North Atlantic Treaty Organization.

The practical conclusion from the available information is clear: version 10.1.20 or the appropriate fix should be installed immediately, followed by an examination of logs and files for signs of compromise. However, the source does not specify the scope of the campaign, the identity of the attackers, or whether the patched version covers all ZCS branches—points that require follow-up from Zimbra and incident response teams.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news