The Cybersecurity and Infrastructure Security Agency (CISA) on Aug. 21 added an actively exploited bug in the Zimbra Collaboration Suite to its Known Exploited Vulnerabilities (KEV) list.Zimbra released a patch for high-severity CVSS 8.9 bug CVE-2026-73570 on July 20, and as of Friday, Aug. 21, CISA gave federal agencies three days to make the patch.The National Institute of Standards and Technology (NIST) explained that unauthenticated attackers can gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component.Security pros believe that teams should take this one seriously because Russia-linked advanced persistent threat (APT) groups continue to attack Zimbra users, many of which are government agencies, universities, and state institutions in Brazil, Argentina, and several European governments.“That user base is also why APT28, APT29, and Winter Vivern have all targeted Zimbra in separate campaigns over the past three years,” said Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs. “The platform those government targets chose is the same one of those threat actors keep exploiting.”Krell said the exposure goes well beyond individual inboxes: a compromised Zimbra server can give an attacker access to email, calendars, contacts, shared files, and credentials across the organization. For a ministry or university running tens of thousands of accounts, a single server compromise potentially exposes who in the organization talks to whom, about what, and when, said Krell."This is Zimbra's fifth KEV entry this year, and state-linked crews keep coming back for a reason,” said Itai Goldman, co-founder and CTO at Miggo Security. “A mail server is not a single box. Zimbra is a hosted deployment, not SaaS. It’s every credential, password reset, and sensitive attachment in the organization sitting behind a single unauthenticated request.Goldman explained that Zimbra's user base is self-selected for sensitivity: ministries, defense contractors, and public institutions that keep mail on-prem for data sovereignty. Goldman said server organizations that cannot patch right away need to understand that this one never touches HTTP, so nothing at the perimeter will see it coming.Jason Soroko, senior fellow at Sectigo, said CISA’s three-day order reflects two facts: exploitation is confirmed, and the vulnerable path can be reached without credentials through SMTP when Zimbra’s optional SNMP package and notifications are enabled.Soroko added that the deeper risk here is that a collaboration server such as Zimbra acts as institutional memory and a relationship map: email, calendars, contacts, files, delegated access, and account messages can reveal how work moves and who can authorize it.“The irony is that many organizations choose Zimbra for sovereignty and control,” said Soroko. “A compromised server can turn that concentration of trusted data into an attacker’s operating map.”
Vulnerability Management, Patch/Configuration Management
CISA adds Zimbra Collaboration Suite bug to exploited vulnerabilities list
(Credit: Timon – stock.adobe.com)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
