Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities Dark Reading

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

  • What: A critical zero-day vulnerability in Zimbra is being actively exploited.
  • Impact: Federal agencies are at risk of full system compromise.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources VULNERABILITIES & THREATS APPLICATION SECURITY CYBER RISK THREAT INTELLIGENCE NEWS Exploited Zimbra Flaw Highlights Shrinking Window to Patch CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications. Jai Vijayan,Contributing Writer August 24, 2026 4 Min Read SOURCE: OPTURADESIGN VIS SHUTTERSTOCK Federal agencies have until the end of Monday to patch a bug in the Zimbra unified communications suite that allows unauthenticated remote code execution. The directive came after CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Friday, following reports of active exploitation. The bug, tracked as CVE-2026-73570, lets attackers execute arbitrary commands on Zimbra Collaboration Suite servers that have SNMP notifications enabled, which is a configuration turned on by default in vulnerable versions. "Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in the execution of arbitrary operating system commands as the Zimbra user," the vulnerability disclosure said. In a government or corporate setting, an attacker would be able to infer a lot about how an entty operates internally by compromising a Zimbra server, explains Robert Costello, chief digital and information officer at Merlin Group. While a Zimbra environment compromise might not yield a network diagram, it could give attackers valuable intelligence in the way of messages, calendars, contacts and attachments, which can reveal an organization's administrators, technology vendors, internal naming conventions, maintenance schedules, and security processes. That intelligence can help attackers map how an organization operates and plan or facilitate follow-on attacks, Costello tells Dark Reading. Related:N-able Bug Exposes Password Vault Master Keys Cyberattackers' Exploitation Timeline Shortens The bug is the latest example of how the window for organizations to address newly disclosed vulnerabilities is shrinking, leaving security teams with less time to assess risks, test fixes, and get patches deployed before attackers strike. Zimbra disclosed CVE-2026-73570 on June 26 and released a patched version of Zimbra Collaboration Suite (ZCS) (v10.1.20) on July 20. At the time, the company described the updated version as containing fixes for multiple critical vulnerabilities, including CVE-2026-73750, and urged affected organizations to migrate to the new version as soon as possible. Less than a month later, on Aug. 16, Poland's national Computer Emergency Response Team (CERT Polska) warned of an ongoing campaign targeting the Zimba vulnerability, and asked organizations to contact the agency if they found any signs of exploit activity. Four days later, on Friday, Aug. 21, CISA added CVE-2026-73570 to its KEV catalog and gave federal civilian executive branch agencies until end of Aug. 24 to mitigate the flaw in their environments or stop using the technology till they do. Related:'CoSnitch' Attack Tricked Copilot Into Mapping Out Architecture CISA moved to a three-day patching deadline for critical vulnerabilities in June, citing growing concerns about AI-enabled exploit development and attack activity. The agency's Binding Operative Directive (BOD) 26-04 established a tiered remediation model that also allows agencies to defer less critical flaws for later remediation. A Focus on High Priority Bugs "CISA’s three-day order reflects two facts," says Jason Soroko, senior fellow at Sectigo. "Exploitation is confirmed, and the vulnerable path can be reached without credentials through SMTP when Zimbra's optional SNMP package and notifications are enabled." Patching can help close the initial entry point, but it does not remove malware or persistence installed before the update, he cautions. "Operators should treat an exposed vulnerable server as an incident response case, not a routine patch, and review the logs and file locations identified by CERT Polska." The latest Zimbra flaw is one of several that organizations have had to deal with on an emergency basis in recent years. In July, the FBI and international law enforcement agencies warned of Russia's "Laundry Bear," an advanced persistent threat (APT) group, exploiting CVE-2025-66376, a stored cross-site scripting (XSS) flaw in Zimbra's Classic UI, in a campaign that had been ongoing for at least a year. Last year, researchers at StrikeReady Labs reported observing a threat actor masquerading as the Libyan Navy's Office of Protocol targeting the Brazilian military via a Zimbra zero-day vulnerability. Related:The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed Time to Treat Security Patching as Incident Response? At a broader level, the shrinking gap between vulnerability disclosure and exploitation means organizations can no longer rely on patching cycles that take days or weeks like before. AI is making it significantly easier for attackers to analyze vulnerability disclosures and patch changes, identify what was fixed, and quickly develop working exploits, says John Strand, owner at Black Hills Information Security. "Organizations have to be ready to rapidly respond to patches," Strands says. "We can't push everything into a once-a-month patching cycle anymore because the patch may arrive today and the working exploit could follow in less than three days." Strand says the time may be here for organizations to start treating some patching requirements — like the ones with three-day deadlines — more as incident response rather than just patching. "We simply may not have the time to sit and wait for patches to be validated and tested as thoroughly as organizations traditionally would like," he says. "That's absolutely going to impact operations. It's absolutely going to create problems. But that's the paradigm we’re in right now." About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion More Webinars You May Also Like VULNERABILITIES & THREATS Cheap Hardware Module Bypasses AMD, Intel Memory Encryption by Rob Wright NOV 25, 2025 VULNERABILITIES & THREATS Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs by Jai Vijayan NOV 11, 2025 VULNERABILITIES & THREATS Microsoft Issues Emergency Patch for Critical Windows Server Bug by Rob Wright OCT 24, 2025 VULNERABILITIES & THREATS 'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails by Nate Nelson SEP 19, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBER RISK What We Missed: Delta Flight Disrupted With Wi-Fi Hack byRob Wright,Alexander Culafi AUG 20, 2026 CYBERATTACKS & DATA BREACHES Agentic AI Presents New Insider Threat Model for Orgs AUG 19, 2026 CYBERSECURITY OPERATIONS Mission-Driven Security: Inside a Global Bank's Defense byKristina Beek AUG 14, 2026 Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW

Share this article