CISA gives federal agencies 3 days to patch actively exploited Zimbra RCE bug
CISA has ordered federal civilian agencies to fix CVE-2026-73570, a Zimbra Collaboration Suite flaw allowing unauthenticated attackers to run arbitrary commands via crafted SMTP requests when SNMP notifications are enabled. Zimbra released a fix in version 10.1.20 on July 20, but CERT Polska flagged active exploitation last week, and Shadowserver has already identified over 270 compromised Zimbra servers among more than 12,000 exposed online.