Advisories
CISA Adds Zimbra OS Command Injection CVE‑2026‑73570 to KEV Catalog
CISA has just added CVE‑2026‑73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities (KEV) list after confirmed active exploitation. Federal agencies are now required to patch this flaw immediately under BOD 26‑04, while all organizations are urged to adopt a risk‑based remediation strategy. The KEV catalog will expand as more exploited CVEs surface, and entities can nominate new entries via CISA’s KEV Nomination Form.
In a recent update, the Cybersecurity and Infrastructure Security Agency (CISA) has appended CVE‑2026‑73570 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, an OS command injection in Zimbra Collaboration Suite (ZCS), allows attackers to execute arbitrary commands on affected systems—granting full control once exploited.
What This Means for Federal Agencies
- Under BOD 26‑04, federal civilian executive branch agencies must prioritize rapid remediation of KEV-listed CVEs on publicly exposed assets that could lead to total control.
- Agencies must also verify whether an attacker has already compromised a system before applying a patch.
- Lower‑risk vulnerabilities may be deferred, but the focus remains on KEV entries.
Implications for the Private Sector
- While BOD 26‑04 applies only to federal agencies, CISA recommends all organizations adopt a risk‑based approach and treat KEV catalog flaws as high‑priority.
- Organizations should review Zimbra deployments, apply the latest patch, and monitor for signs of exploitation.
- Security teams can use the KEV catalog as a quick reference for the most dangerous, actively exploited CVEs.
“CISA will continue to add vulnerabilities that meet our criteria,” says the agency. “If you know of an exploited CVE not yet listed, submit it through our KEV Nomination Form.”
How to Submit a Potential KEV
- Provide the CVE identifier, evidence of active exploitation, and clear mitigation guidance.
- Submit through CISA’s KEV Nomination Form available on the agency’s website.
- Once reviewed, the vulnerability may be added to the catalog, triggering higher remediation priority.