Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Bitcoin’s Next Test Is $80,000 as Jackson Hole Meeting Looms

    August 24, 2026

    Primary Effort ‘Changed the Conversation’ Around Wyoming’s Public Lands

    August 24, 2026

    NKT cranks up the heat on HVDC power cables with 90°C technology

    August 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Bitcoin’s Next Test Is $80,000 as Jackson Hole Meeting Looms
    • Primary Effort ‘Changed the Conversation’ Around Wyoming’s Public Lands
    • NKT cranks up the heat on HVDC power cables with 90°C technology
    • Dr. Craig Towers’ Research on Pregnant Opioid Users Has Major Flaws, Auditors and Experts Say — ProPublica
    • 91-year-old woman wasn’t arrested for stealing costly heart medication for husband, despite claims
    • India used pellets, grenades on Gen Z protests: What Amnesty report reveals | Explainer
    • Minister tells social media firms to remove posts that ‘celebrate’ dangerous driving after A66 crash | Social media
    • CISA orders urgent patching of actively exploited Zimbra flaw
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA orders urgent patching of actively exploited Zimbra flaw

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 24, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days.

    The Zimbra security team patched the security flaw (tracked as CVE-2026-73570) in version 10.1.20, released on July 20.

    Successful exploitation allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled on the targeted system.

    image

    “Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user,” it explained.

    CISA’s warning comes after CERT Polska, the Polish Computer Emergency Response Team (CERT), first flagged the vulnerability as targeted in the wild last Monday.

    While threat security watchdog Shadowserver tracks more than 12,000 Zimbra servers exposed on the Internet, there is no information on how many are honeypots or have already been secured against attacks exploiting the CVE-2026-73570 flaw.

    Zimbra Collaboration Suite servers exposed online
    Zimbra Collaboration Suite servers exposed online (Shadowserver)

    ​On Friday, CISA confirmed CERT Polska’s alert, added the flaw to its KEV catalog, and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, by August 24.

    Although CISA didn’t share any information on these ongoing attacks, the Polish CERT team asked security teams to check logs for suspicious activity, such as the Zimbra service restarting unexpectedly, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days.

    ZCS is a popular email and collaboration suite used by hundreds of millions of organizations and people worldwide, including hundreds of government agencies and thousands of businesses.

    Zimbra security issues are commonly targeted in the wild and have been used to steal sensitive data from vulnerable email servers in recent years.

    Most recently, Seqrite Labs researchers revealed in March that APT28 (a state-sponsored threat group linked to Russia’s military intelligence service) was exploiting a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers.

    In October 2024, U.S. and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear) linked to Russia’s Foreign Intelligence Service were targeting Zimbra servers using a flaw previously exploited to steal email account credentials.

    Russian Winter Vivern cyber spies have also abused a reflected Cross-Site Scripting (XSS) vulnerability to steal emails belonging to NATO-aligned individuals and organizations via Zimbra webmail portals.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    actively CISA Exploited Flaw orders Patching urgent Zimbra
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

    Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund

    ToxicPanda Android malware uses VPN permissions to block Google Play

    Hardware Makers Implement Post-Quantum Cryptography

    Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

    CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Bitcoin’s Next Test Is $80,000 as Jackson Hole Meeting Looms

    August 24, 2026

    Primary Effort ‘Changed the Conversation’ Around Wyoming’s Public Lands

    August 24, 2026

    NKT cranks up the heat on HVDC power cables with 90°C technology

    August 24, 2026

    Dr. Craig Towers’ Research on Pregnant Opioid Users Has Major Flaws, Auditors and Experts Say — ProPublica

    August 24, 2026
    Latest Posts

    Little Italy group, city of San Diego at ‘stalemate’ over bike lane

    July 28, 2026

    Blazing like 10 billion suns: NASA’s Swift sees a wandering black hole devouring a star

    July 28, 2026

    Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Bitcoin’s Next Test Is $80,000 as Jackson Hole Meeting Looms

    August 24, 2026

    Primary Effort ‘Changed the Conversation’ Around Wyoming’s Public Lands

    August 24, 2026

    NKT cranks up the heat on HVDC power cables with 90°C technology

    August 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.