Federal agencies have until the end of Monday to patch a bug in the Zimbra unified communications suite that allows unauthenticated remote code execution. The directive came after CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Friday, following reports of active exploitation.
The bug, tracked as CVE-2026-73570, lets attackers execute arbitrary commands on Zimbra Collaboration Suite servers that have SNMP notifications enabled, which is a configuration turned on by default in vulnerable versions.
“Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in the execution of arbitrary operating system commands as the Zimbra user,” the vulnerability disclosure said.
In a government or corporate setting, an attacker would be able to infer a lot about how an entty operates internally by compromising a Zimbra server, explains Robert Costello, chief digital and information officer at Merlin Group. While a Zimbra environment compromise might not yield a network diagram, it could give attackers valuable intelligence in the way of messages, calendars, contacts and attachments, which can reveal an organization’s administrators, technology vendors, internal naming conventions, maintenance schedules, and security processes. That intelligence can help attackers map how an organization operates and plan or facilitate follow-on attacks, Costello tells Dark Reading.
Cyberattackers’ Exploitation Timeline Shortens
The bug is the latest example of how the window for organizations to address newly disclosed vulnerabilities is shrinking, leaving security teams with less time to assess risks, test fixes, and get patches deployed before attackers strike.
Zimbra disclosed CVE-2026-73570 on June 26 and released a patched version of Zimbra Collaboration Suite (ZCS) (v10.1.20) on July 20. At the time, the company described the updated version as containing fixes for multiple critical vulnerabilities, including CVE-2026-73750, and urged affected organizations to migrate to the new version as soon as possible.
Less than a month later, on Aug. 16, Poland’s national Computer Emergency Response Team (CERT Polska) warned of an ongoing campaign targeting the Zimba vulnerability, and asked organizations to contact the agency if they found any signs of exploit activity. Four days later, on Friday, Aug. 21, CISA added CVE-2026-73570 to its KEV catalog and gave federal civilian executive branch agencies until end of Aug. 24 to mitigate the flaw in their environments or stop using the technology till they do.
CISA moved to a three-day patching deadline for critical vulnerabilities in June, citing growing concerns about AI-enabled exploit development and attack activity. The agency’s Binding Operative Directive (BOD) 26-04 established a tiered remediation model that also allows agencies to defer less critical flaws for later remediation.
A Focus on High Priority Bugs
“CISA’s three-day order reflects two facts,” says Jason Soroko, senior fellow at Sectigo. “Exploitation is confirmed, and the vulnerable path can be reached without credentials through SMTP when Zimbra’s optional SNMP package and notifications are enabled.”
Patching can help close the initial entry point, but it does not remove malware or persistence installed before the update, he cautions. “Operators should treat an exposed vulnerable server as an incident response case, not a routine patch, and review the logs and file locations identified by CERT Polska.”
The latest Zimbra flaw is one of several that organizations have had to deal with on an emergency basis in recent years. In July, the FBI and international law enforcement agencies warned of Russia’s “Laundry Bear,” an advanced persistent threat (APT) group, exploiting CVE-2025-66376, a stored cross-site scripting (XSS) flaw in Zimbra’s Classic UI, in a campaign that had been ongoing for at least a year. Last year, researchers at StrikeReady Labs reported observing a threat actor masquerading as the Libyan Navy’s Office of Protocol targeting the Brazilian military via a Zimbra zero-day vulnerability.
Time to Treat Security Patching as Incident Response?
At a broader level, the shrinking gap between vulnerability disclosure and exploitation means organizations can no longer rely on patching cycles that take days or weeks like before. AI is making it significantly easier for attackers to analyze vulnerability disclosures and patch changes, identify what was fixed, and quickly develop working exploits, says John Strand, owner at Black Hills Information Security.
“Organizations have to be ready to rapidly respond to patches,” Strands says. “We can’t push everything into a once-a-month patching cycle anymore because the patch may arrive today and the working exploit could follow in less than three days.”
Strand says the time may be here for organizations to start treating some patching requirements — like the ones with three-day deadlines — more as incident response rather than just patching.
“We simply may not have the time to sit and wait for patches to be validated and tested as thoroughly as organizations traditionally would like,” he says. “That’s absolutely going to impact operations. It’s absolutely going to create problems. But that’s the paradigm we’re in right now.”

Comments are closed