Exploited Zimbra Flaw Highlights Shrinking Window to Patch

Used in attacksCriticalDark Reading · Jai Vijayan·

At a glance

Severity
Critical
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-73570
Industries
Government
Reported by
1 outlet

CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

Vulnerabilities referenced

  • Synacor Zimbra Collaboration Suite (ZCS)

    Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

    Used in attacks

    Added to CISA's list 2026-08-21 · Patch or advisory available

    Full record →

Coverage

One outlet has carried this so far.

  1. Dark ReadingEstablished SourceFirst reported

    2026-08-24 21:46 UTC

Related stories