Zimbra security advisory (AV26-816) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-816 Date: August 14, 2026 Updated: August 21, 2026 As of August 13, 2026, Zimbra is affected by vulnerabilities in the following product: Collaboration - Prior to 10.1.20 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On August 21, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-73570 to their Known Exploited Vulnerabilities (KEV) Database. Zimbra Security Advisories - Zimbra: Tech Center Zimbra Responsible Disclosure Policy - Zimbra: Tech Center Zimbra: Blog - All Things Zimbra CISA KEV: CVE-2026-73570
CSIRTS triage
- What
- Zimbra Collaboration versions prior to 10.1.20 contain vulnerabilities.
- Who is affected
- Zimbra Collaboration installations running versions before 10.1.20 are affected.
- Urgency
- Moderate; no active exploitation reported but vulnerabilities are confirmed.
- Action
- Upgrade Zimbra Collaboration to version 10.1.20 or later as patches become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Collaboration
Get an email when a new Collaboration advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/zimbra-security-advisory-av26-816
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-73570Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 61% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-73570 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedZimbra Multiple Vulnerabilitieshkcert
- unknownexploitedNCSC-2026-0324 [1.00] [M/H] Kwetsbaarheid verholpen in Zimbra Collaboration Suitencsc-nl
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerabilitycisa-kev
- unknownexploitedMultiple vulnerabilities in Synacor Zimbra Collaboration (August 19, 2026)cert-fr-avis
- highCVE-2026-73570: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when…nvd
More from Canadian Centre for Cyber Security
- unknownIvanti security advisory (AV26-897)2026-09-08
- unknownMicrosoft security advisory – September 2026 monthly rollup (AV26-896) – Update 12026-09-08
- unknownAdobe security advisory (AV26-888) – Update 12026-09-08
- unknownN-able security advisory (AV26-885) – Update 12026-09-08
- unknownCommvault security advisory (AV26-895)2026-09-08