Back to advisories

CISA orders urgent patching of actively exploited Zimbra flaw

Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.

CRITICALAdvisoryAug 24, 2026
Action required
Immediately identify all Zimbra Collaboration Suite instances in your environment. Prioritize patching to version 10.1.20 or later. If patching cannot be completed within 24 hours, isolate affected systems from the network.
Affected products
Zimbra Collaboration SuiteZimbraZCS