LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › CISA Adds Zimbra OS Command Injection to KEV Catalog

CRITICAL severityReportedHow we verify

CISA Adds Zimbra OS Command Injection to KEV Catalog: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 21, 2026
CISA Adds Zimbra OS Command Injection to KEV Catalog

Reported August 21, 2026.

CRITICAL
Severity
1
Data types exposed
August 21, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

CISA added a Zimbra OS command injection vulnerability to its Known Exploited Vulnerabilities catalog on August 21, 2026, after the flaw was publicly disclosed. Organizations should check whether their systems are affected and apply the recommended mitigations promptly.

Severity & verification
CRITICAL severityReported
Data types not itemised.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Federal cybersecurity authorities have again flagged active exploitation of a serious flaw in widely deployed collaboration software, underscoring how quickly unpatched internet-facing mail systems can become entry points for attackers. On August 21, 2026, the Cybersecurity and Infrastructure Security Agency added a Zimbra Collaboration Suite operating-system command-injection vulnerability to its Known Exploited Vulnerabilities catalog after confirming real-world abuse.

The listing does not itself describe a single named breach with a known victim count. It does signal that unauthenticated attackers have already used the flaw to run commands on affected servers, creating system-level access risk for any organization still running the vulnerable software. Prompt patching is the clear priority.

What happened

CISA added CVE-2026-73570, described as an OS command injection issue in Zimbra Collaboration Suite, to the Known Exploited Vulnerabilities catalog on August 21, 2026. The addition rested on evidence of active exploitation in the wild. According to the disclosure, the vulnerability could allow unauthenticated attackers to execute arbitrary operating-system commands as the Zimbra user by sending crafted SMTP requests.

Public detail does not identify specific compromised organizations, the number of affected systems, or the scale of any resulting intrusions. People affected are listed as unknown. The named exposure is system access. Organizations that use Zimbra were urged to apply patches immediately. No further technical indicators, victim lists, or confirmed data-theft volumes appear in the available record.

How a breach like this happens

Incidents of this type typically begin when an internet-facing service—here, a mail and collaboration platform—contains a flaw that lets an outsider reach the underlying operating system without valid credentials. Attackers scan for exposed instances, craft requests that trigger the injection point, and obtain a foothold running as the application’s service account. From that position they can install persistence mechanisms, move laterally, or harvest configuration and message data if additional weaknesses exist.

Because the initial vector requires no authentication, the window of exposure lasts as long as the vulnerable software remains reachable and unpatched. Background patterns across the industry show repeated delays in treating KEV-catalogued flaws as immediate patching events, especially on mail infrastructure that is difficult to take offline. No specific threat group is attributed in the facts for this listing, and none should be assumed.

About CISA Adds Zimbra OS Command Injection to KEV Catalog

The Cybersecurity and Infrastructure Security Agency is the U.S. federal civilian agency charged with reducing cyber risk to government and critical infrastructure. One of its core tools is the Known Exploited Vulnerabilities catalog, a living list of flaws that have been observed under active attack. Federal civilian agencies face binding deadlines to remediate KEV entries; many private-sector and state organizations treat the same list as a high-priority patching signal.

Zimbra Collaboration Suite is a common on-premises and hosted platform for email, calendaring, and related groupware. Organizations that run it often place the service on the public internet so users can send and receive mail. When a command-injection flaw in such a platform is confirmed as exploited, the consequence is not merely a theoretical software bug: it is a practical path to system access on servers that handle sensitive communications. The KEV addition therefore functions as both a warning and a prioritization directive for every operator still running the affected code.

What data was at risk

The facts name the exposed element as system access. Exact contents of any compromised mailboxes, address books, or stored files are unconfirmed. No passwords or user credentials are reported as exposed, and this event is not described as a confirmed Zimbra customer data breach.

Organizations that operate collaboration suites typically hold email messages, contact lists, calendar entries, authentication material for the mail service itself, and administrative configuration. Whether any of those categories were actually read or copied in any given exploitation of CVE-2026-73570 remains undisclosed. Readers should treat claims of specific personal-data exposure as unverified unless a separate, detailed notification appears.

Why it matters

Unauthenticated command execution on a mail server can give an attacker a durable foothold. Even after the vulnerability is publicly known, unpatched instances remain usable for reconnaissance, further compromise, or quiet monitoring of traffic. For individuals whose organizations rely on Zimbra, the practical risk is that an attacker who reached the server could, in principle, access messages or accounts hosted there—though that outcome is not confirmed for any particular site in the present record.

For the organizations themselves, the incident highlights a recurring posture problem: internet-facing collaboration platforms left unpatched after a KEV listing. The pattern of delayed remediation on mail infrastructure is described as widespread and still growing. Persistent system access obtained through command injection can outlast the initial disclosure window, raising the cost of later detection and recovery.

If your data was in this breach

No public notification confirms that any specific individual’s data was taken. If your workplace or provider uses Zimbra Collaboration Suite, ask them whether they have applied the patches addressing CVE-2026-73570 and whether they observed suspicious SMTP activity around the time of the KEV addition. Monitor accounts for unusual login or forwarding rules, and treat any separate breach notice from your organization as the authoritative source for next steps.

You can also run a free exposure scan of your email address to check whether your information has already appeared in other known breach datasets. That check does not prove involvement in this Zimbra-related activity, but it can surface credentials or personal details that warrant password changes on unrelated services and heightened vigilance against phishing.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Method

More recent breaches

CISA Adds Two Vulnerabilities to KEV CatalogJuly 10, 2026Denmark CPR Register Unauthorised Access Affects 8.8MOctober 5, 2026CenterPoint Energy Cybersecurity Incident DisclosureSeptember 14, 2026ATF Confirms Cybersecurity Incident on Standalone SystemAugust 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the CISA Adds Zimbra OS Command Injection to KEV Catalog →

Source: CISA

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram