CISA Issues Due Date for Mitigating Actively Exploited Zimbra Collaboration Suite Vulnerability
CISA has set an August 24, 2026, due date for federal agencies to apply mitigations for CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS). This flaw allows an unauthenticated attacker to execute arbitrary operating system commands as the Zimbra user by sending specially crafted SMTP requests. The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on August 21, 2026.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai