CISA Adds Zimbra Command-Injection Bug to KEV
Zimbra ZCS has become a perennial KEV entry. This OS command-injection bug is the latest, and BOD 26-04's remediation clock starts now.
TL;DR
CISA added CVE-2026-73570, a Zimbra Collaboration Suite OS command-injection vulnerability, to its Known Exploited Vulnerabilities catalog Thursday, citing active exploitation. Federal agencies under BOD 26-04 must now prioritize remediation on publicly exposed assets. Zimbra vulnerabilities are a recurring fixture in the KEV catalog. This isn't the first, and it won't be the last.
CVE-2026-73570 is an OS command-injection vulnerability in Zimbra Collaboration Suite. CISA added it to the KEV catalog based on evidence of active exploitation in the wild. Command injection in a collaboration platform is particularly dangerous: successful exploitation can hand an attacker control of the underlying server, the mail store, and every account on the system.
For FCEB agencies, the addition triggers BOD 26-04's remediation requirements. The directive mandates rapid remediation of KEV-listed CVEs on publicly exposed assets that grant total control post-exploitation. It also requires agencies to check whether threat actors compromised affected systems before the patch was applied. That clock is now running.
This isn't Zimbra's first KEV appearance, and the pattern is well-established. Zimbra vulnerabilities surface in the catalog with regularity, a reflection of both the product's attack surface and its prevalence across government and enterprise environments. CISA encourages all organizations, not just FCEB agencies, to adopt risk-based vulnerability management and prioritize KEV-listed vulnerabilities.
Published ·Updated ·Deep Fathom