Actively Exploited Zimbra Flaw Added to CISA's Must-Patch List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, CVE-2026-73570, to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw affects Zimbra Collaboration Suite (ZCS) and is an OS command injection vulnerability, meaning attackers can potentially run unauthorised commands on affected systems. CISA confirmed there is evidence this vulnerability is being actively exploited in the wild.
Command injection vulnerabilities like this one are a common attack method for cybercriminals and can give them significant control over compromised systems. While CISA's Binding Operational Directive 26-04 legally requires U.S. federal agencies to remediate such vulnerabilities on a strict timeline, CISA strongly encourages all organisations — including small and medium businesses — to review their systems and apply patches promptly.
Australian businesses using Zimbra Collaboration Suite for email or collaboration should check whether they are running an affected version and apply available security updates immediately. Vulnerabilities added to the KEV Catalog are ones with confirmed real-world exploitation, making them a higher priority than general software updates.