The Cybersecurity and Infrastructure Security Agency (CISA) on Friday ordered agencies to rapidly patch a vulnerability in the Zimbra Collaboration Suite that malicious actors are exploiting to impersonate users and perform unauthorized actions.
CISA added the Zimbra flaw, tracked as CVE-2026-73570, to its Known Exploited Vulnerabilities catalog and gave agencies three days to patch it. That deadline expired on Monday. It was unclear how many agencies had applied the patch.
The vulnerability relates to Zimbra’s implementation of an add-on package that sends notifications to users. Because the software fails to sanitize untrusted inputs from the package, an attacker could use it to send malicious simple mail transfer protocol (SMTP) requests that would grant them broad access to the target’s Zimbra platform.
Zimbra developer Synacor disclosed the flaw on June 26, but it didn’t release a patched version of its software until July 20.
By mid-August, hackers were exploiting the vulnerability, according to an alert from the Polish government.
Thousands of organizations worldwide, including nearly 700 in the U.S., are still using vulnerable versions of the Zimbra software, according to the open-source intelligence platform Shadowserver. More than 40 organizations in the U.S. have been hacked through the vulnerability, along with dozens of others worldwide, according to Shadowserver.
Cyber threat actors have repeatedly taken advantage of Zimbra vulnerabilities for hacking campaigns. In July, CISA and the National Security Agency warned that Russia-linked hackers were targeting Ukrainian and Western governments and companies using another Zimbra flaw. Previous Zimbra-based attacks have targeted the Brazilian military and organizations in the healthcare and energy sectors.