Attackers exploit a Zimbra bug to run commands on servers

The US Cybersecurity and Infrastructure Security Agency has added a Zimbra Collaboration Suite flaw to its Known Exploited Vulnerabilities catalog, the list CISA keeps only for bugs it has evidence attackers are already using. The entry published on 21 August names CVE-2026-73570, an operating system command injection weakness in the mail and collaboration platform.

CISA's catalog text is short and specific. An unauthenticated attacker can send specially crafted SMTP requests, the ordinary protocol mail servers use to accept incoming messages, and those requests may end in arbitrary operating system commands running as the Zimbra user. No password, no phishing and no prior foothold are involved. The machine that accepts the mail is the machine that runs the commands.

A mail server is a filing cabinet with a door

Zimbra is self-hosted groupware, the on-premises alternative to a hosted mailbox, and it is common in government departments, universities and service providers that want their own mail on their own hardware. That is exactly what makes it attractive to attackers: everything an organization writes down passes through it, and command execution as the Zimbra user puts an intruder inside that flow rather than outside it.

It is also a repeat target. In July, IntelFusions reported on a Russia-linked espionage cluster using a zero-click Zimbra exploit to lift Western government email. That was a different flaw and a different campaign, and nothing in CISA's notice ties the two together. It is context for why a Zimbra bug with live exploitation deserves a same-day response rather than a place in next month's patch cycle.

What the catalog entry leaves out

Quite a lot, and it is worth being clear about it. CISA publishes no CVSS score for this CVE, names no affected or fixed version, does not say who is exploiting it, and does not describe how the crafted SMTP requests are built. That is normal for a KEV addition, which exists to say "this is being used, act now" rather than to serve as technical analysis. Zimbra's own security advisories carry the version detail, and administrators should work from those rather than from anything inferred about the bug from its title. CISA points to no public write-up of the attacks, so the honest position today is that the fact of exploitation is established and the shape of it is not.

Patch it, then check whether you were already hit

The KEV listing pulls this into Binding Operational Directive 26-04, which requires US federal civilian agencies to prioritize rapid remediation of high-risk catalog entries on publicly exposed assets, specifically those that hand over total control of the asset after exploitation, while deferring lower-risk work. BOD 26-04 also sets an expectation that agencies check whether attackers got in before the patch landed, which is the part everyone else should copy. A patched Zimbra server that was internet-facing last week is a patched server, not a clean one.

The directive binds only federal agencies, but CISA's advice to everyone else is the same: treat catalog entries as the queue that jumps ahead of the rest. For a mail server reachable from the internet, that queue has one item in it today.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions