CISA puts an exploited Zimbra command-injection bug on the KEV list
CVE-2026-73570 is unauthenticated command injection in SNMP notification processing as the zimbra user. CERT Polska saw it in the wild. Federal agencies had to patch by August 24.

On August 24 BleepingComputer reported that CISA added CVE-2026-73570 to the Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by August 24. CERT Polska had already seen the bug in the wild. Zimbra fixed it on July 20 in ZCS 10.1.20.
What we know
- CVE-2026-73570 was added to CISA’s KEV list; federal agencies had a patch deadline of August 24.
- CERT Polska reported in-the-wild exploitation.
- The fix shipped July 20 in Zimbra Collaboration Suite 10.1.20.
- The bug is unauthenticated command injection in SNMP notification processing and runs as the zimbra user; SNMP notifications must be on.
- Shadowserver counted more than 12,000 exposed Zimbra servers and more than 270 with exploit artifacts.
Takeaways
- The federal clock and the KEV listing landed on the same day as this report.
- The injection is reachable only when SNMP notifications are enabled.
- Hundreds of internet-facing servers already show exploit leftovers.
Source: BleepingComputer / CISA


