Urgent Zimbra Email Flaw Under Attack: Patch Now, Experts Warn
A serious security flaw in Zimbra, a widely used email and collaboration platform, is being actively exploited by attackers, according to Dark Reading. The vulnerability, tracked as CVE-2026-73570, allows attackers to gain complete control over a user's communications if left unpatched.
The US Cybersecurity and Infrastructure Security Agency (CISA) has responded with an unusually tight three-day deadline for federal agencies to apply the fix. While this directive technically applies to US government bodies, it signals just how dangerous this flaw is considered and how quickly attackers are moving to exploit it once vulnerabilities become public.
For Australian small businesses, the takeaway isn't the deadline itself but the trend it represents: the time between a vulnerability being disclosed and it being actively exploited in the wild continues to shrink. Businesses using Zimbra or similar email platforms should treat this as a priority patching issue, as full takeover of email accounts can lead to data theft, business email compromise, and further attacks on customers or partners.