AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 25 Aug, 12:11

CISA orders emergency patching after hackers actively exploit a critical Zimbra Collaboration Suite flaw

CISA ordered U.S. federal agencies to patch a critical, unauthenticated Zimbra Collaboration Suite flaw within three days after CERT Polska confirmed hackers were actively exploiting it. Per BleepingComputer and Security Affairs.

CERT Polska, Poland's national cyber emergency response team, confirmed that attackers are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that lets unauthenticated remote attackers execute arbitrary shell commands as the zimbra user. The flaw, rated 8.9 on the CVSS scale, affects installations with the optional zimbra-snmp package installed, SNMP notifications enabled, and the swatchdog service running - swatchdog is enabled by default on most installations. Zimbra patched the bug in version 10.1.20, released July 20, 2026, but active exploitation was confirmed 28 days later. On August 21, CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered U.S. Federal Civilian Executive Branch agencies to secure their systems by August 24. Security research group Shadowserver tracks more than 12,000 Zimbra Collaboration Suite servers exposed on the internet, with no public data on how many remain unpatched. Sources: BleepingComputer, Security Affairs.

#cyber
Published on