The collaboration software’s developer took almost a full month to patch the flaw after disclosing it.
The <a href="https://bitcomme.com/ai-agents-are-a-cybersecurity-nightmare-thats-only-just-begun/” title=”AI Agents Are a Cybersecurity Nightmare That's Only Just Begun”>Cybersecurity and Infrastructure Security Agency (CISA) on Friday ordered agencies to rapidly patch a vulnerability in the Zimbra Collaboration Suite that malicious actors are exploiting to impersonate users and perform unauthorized actions.
CISAadded the Zimbra flaw, tracked asCVE-2026-73570, toits Known Exploited Vulnerabilities catalogand gave agencies three days to patch it. That deadline expired on Monday. It was unclear how many agencies had applied the patch.
The vulnerability relates to Zimbra’s implementation of an add-on package that sends notifications to users. Because the software fails to sanitize untrusted inputs from the package, an attacker could use it to send malicious simple mail transfer protocol (SMTP) requests that would grant them broad access to the target’s Zimbra platform.
Zimbra developer Synacor disclosed the flaw on June 26, but it didn’t release a patched version of its software until July 20.
Thousands of organizations worldwide, including nearly 700 in the U.S., arestill using vulnerable versionsof the Zimbra software, according to the open-ns in the U.S.have been hackedthrough the vulnerability, along with dozens of others worldwide
Cyber threat actors have repeatedly taken advantage of Zimbra vulnerabilities for hacking campaigns. In July, CISA and the National Security Agency warned thatRussia-linked hackers were targetingUkrainian and Western governments and companies using another Zimbra flaw. Previous Zimbra-based attacks have targetedthe Brazilian militaryandorganizations in the healthcare and energy sectors.
Filed Under:Breaches,Vulnerability,Threats
