CISA Warns of Zimbra OS Command Injection Vulnerability Active Exploitation (CVE-2026-73570)
CISA added actively exploited Zimbra OS command injection flaw CVE-2026-73570 to its KEV catalog, urging users to patch by August 24, 2026.
CISA warned that Zimbra vulnerability CVE-2026-73570 is being actively exploited in the wild and added it to its Known Exploited Vulnerabilities Catalog. The OS command injection flaw resides in the SNMP monitoring component and is exploitable when SNMP notifications are enabled. Users, including US federal agencies subject to BOD deadlines, were urged to apply fixes before the August 24, 2026 deadline. Qualys ThreatPROTECT published tracking coverage of the KEV addition.