“zimbra” — 35 distilled results

CISA orders urgent patching of actively exploited Zimbra flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a three-day deadline on August 24, 2026, for federal civilian agencies to patch CVE-2026-73570, an actively exploited vulnerability in Zimbra Collaboration Suite that allows full takeover of user communications.

Hackers compromise over 270 Zimbra email servers via remote code execution

Threat actors exploited a high-severity vulnerability in Zimbra Collaboration Suite to remotely execute code and compromise over 270 Zimbra instances as of August 25, 2026. The ongoing attack campaign represents a significant breach affecting email infrastructure across multiple organizations.

Critical Zimbra email vulnerability actively exploited globally

CERT Polska warned on 20 August 2026 that threat actors were actively exploiting a critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite across multiple systems. Zimbra released patches for nine vulnerabilities, with the RCE flaw posing immediate risk to mail server installations worldwide.

CVE-2026-93643: Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request

CVE-2026-93643 - zimbra collaboration suite (zcs) If Zimbra’s OnlyOffice document feature is enabled, a remote attacker who can view a public document can trick the system into writing files to any location and then… Too many irrelevant or confusing CVEs? com #zimbra #CVE #infosec When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse.