Federal agencies have until the end of Monday to patch a bug in the Zimbra unified communications suite that allows unauthenticated remote code execution. The directive came after CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Friday, following reports of active exploitation.
The bug, tracked as CVE-2026-73570, lets attackers execute arbitrary commands on Zimbra Collaboration Suite servers that have SNMP notifications enabled, which is a configuration turned on by default in vulnerable versions.
"Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in the execution of arbitrary operating system commands as the Zimbra user," the vulnerability disclosure said.
In a government or corporate setting, an attacker would be able to infer a lot about how an entty operates internally by compromising a Zimbra server, explains Robert Costello, chief digital and information officer at Merlin Group. While a Zimbra environment compromise might not yield a network diagram, it could give attackers valuable intelligence in the way of messages, calendars, contacts and attachments, which can reveal an organization's administrators, technology vendors, internal naming conventions, maintenance schedules, and security processes. That intelligence can help attackers map how an organization operates and plan or facilitate follow-on attacks, Costello tells Dark Reading.