CISA has ordered U.S. Federal Civilian Executive Branch agencies to secure systems against an actively exploited Zimbra Collaboration Suite flaw within three days, according to BleepingComputer. The agency added the vulnerability to its Known Exploited Vulnerabilities catalog on Friday and set an August 24 deadline for federal remediation. The flaw is tracked as CVE-2026-73570. BleepingComputer reports that Zimbra patched it in ZCS version 10.1.20, which was released on July 20. The affected product is Zimbra Collaboration Suite, an email and collaboration platform used by government agencies and businesses. The vulnerability can allow unauthenticated remote code execution, according to the report. The issue sits in the Simple Network Management Protocol monitoring component and depends on SNMP notifications being enabled on the targeted system. BleepingComputer, citing Zimbra’s description, says the weakness involves improper sanitization of untrusted input during SNMP notification processing, allowing specially crafted SMTP requests to trigger operating-system command execution as the Zimbra user. The public warning followed an alert from CERT Polska, Poland’s computer emergency response team, which BleepingComputer says first flagged the vulnerability as being targeted in the wild last Monday. CISA later confirmed that alert, though the agency did not publish details about the observed attacks in the material provided. The exposure picture is still incomplete. BleepingComputer reports that Shadowserver tracks more than 12,000 Zimbra servers exposed to the internet, but says there is no information on how many of those systems are honeypots or have already been secured against CVE-2026-73570. CERT Polska’s guidance, as summarized by BleepingComputer, asks security teams to inspect logs for signs such as unexpected Zimbra service restarts. It also recommends checking for files created by the zimbra user during the past 30 days in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/. The alert lands in a product category that has been repeatedly targeted. BleepingComputer notes prior Zimbra-focused activity attributed by researchers and government agencies to groups including APT28, APT29, and Winter Vivern, with earlier campaigns involving cross-site scripting flaws and credential theft against email systems. Those historical cases do not establish who is behind the current exploitation, but they explain why defenders treat internet-facing mail and collaboration servers as high-value targets. Who benefits: Organizations that already updated to ZCS 10.1.20, or can rapidly verify patch status and review logs, are better positioned. Security teams also benefit from CERT Polska’s concrete log-review guidance. Who's exposed: Operators running affected Zimbra systems before the fixed version are exposed, especially where SNMP notifications are enabled. Internet-facing deployments deserve priority given Shadowserver’s reported count of more than 12,000 exposed Zimbra servers.