CISA Adds One Known Exploited Vulnerability to Catalog
What happened
CISA has added a critical OS command injection vulnerability in the Zimbra Collaboration Suite, CVE-2026-73570, to its Known Exploited Vulnerabilities catalog. This flaw is being actively used by threat actors as a frequent attack vector for federal enterprise compromise.
Why it ranks #1
Confirmed active exploitation of an enterprise collaboration suite added to CISA's KEV catalog places this in the highest urgency tier.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Prioritize patching Zimbra Collaboration Suite installations immediately per CISA directives.
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed