CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Zimbra security advisory (AV26-816) – Update 1

unknownknown exploitedpublic exploitCVE-2026-73570
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-816 Date: August 14, 2026 Updated: August 21, 2026 As of August 13, 2026, Zimbra is affected by vulnerabilities in the following product: Collaboration - Prior to 10.1.20 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On August 21, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-73570 to their Known Exploited Vulnerabilities (KEV) Database. Zimbra Security Advisories - Zimbra: Tech Center Zimbra Responsible Disclosure Policy - Zimbra: Tech Center Zimbra: Blog - All Things Zimbra CISA KEV: CVE-2026-73570

CSIRTS triage

vendor: Zimbraproduct: CollaborationOtheraffected: prior to 10.1.20
What
Zimbra Collaboration versions prior to 10.1.20 contain vulnerabilities.
Who is affected
Zimbra Collaboration installations running versions before 10.1.20 are affected.
Urgency
Moderate; no active exploitation reported but vulnerabilities are confirmed.
Action
Upgrade Zimbra Collaboration to version 10.1.20 or later as patches become available.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Collaboration

Get an email when a new Collaboration advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-21
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/zimbra-security-advisory-av26-816

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-73570coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security