The Cybersecurity and Infrastructure Security Agency has ordered U.S. federal agencies to patch an actively exploited vulnerability in the Zimbra Collaboration Suite within three days. The directive applies to the Federal Civilian Executive Branch and requires systems to be secured by August 24. The order follows a confirmation on Friday from CISA that the flaw, tracked as CVE-2026-73570, is being targeted in the wild.

Zimbra patched the security flaw in version 10.1.20, released on July 20. The vulnerability is a command injection weakness in the SNMP monitoring component that allows unauthenticated attackers to achieve remote code execution when SNMP notifications are enabled. An attacker can send specially crafted SMTP requests that may execute arbitrary operating system commands as the Zimbra user due to improper sanitization of untrusted input during SNMP notification processing.

The warning originated from CERT Polska, the Polish Computer Emergency Response Team, which first flagged the flaw as targeted last Monday. While the threat security watchdog Shadowserver tracks more than 12,000 Zimbra servers exposed on the Internet, it remains unclear how many are honeypots or have already been secured against attacks exploiting this flaw. CISA did not share details on the ongoing attacks.

The Polish CERT team advised security teams to review logs for suspicious activity, including unexpected restarts of the Zimbra service. They also recommended checking for files created by the zimbra user over the last 30 days in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders. These indicators may reveal signs of compromise.

Zimbra Collaboration Suite is a widely used email and collaboration platform serving hundreds of millions of users, including hundreds of government agencies and thousands of businesses. Zimbra security issues have frequently been exploited in the wild and used to steal sensitive data from vulnerable email servers in recent years. In March, Seqrite Labs researchers reported that APT28, a state-sponsored threat group linked to Russia's military intelligence service, was exploiting a stored cross-site scripting vulnerability against Ukrainian government Zimbra servers.

In October 2024, U.S. and UK cyber agencies warned that APT29, also tracked as Midnight Blizzard and Cozy Bear and linked to Russia's Foreign Intelligence Service, was targeting Zimbra servers using a flaw previously exploited to steal email account credentials. Russian Winter Vivern cyber spies have also abused a reflected cross-site scripting vulnerability to steal emails belonging to NATO-aligned individuals and organizations via Zimbra webmail portals. These incidents underscore the persistent threat landscape facing Zimbra deployments.

More cybersecurity news from TechManNews.