Exploited Zimbra Flaw Highlights Shrinking Window to Patch
Active exploitation (KEV)
What to do
- On CISA KEV — actively exploited. Patch immediately.
CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
CVE · detail
- CVE-2026-73570KEVEPSS 21%NVD ↗