← Incidents
INCIDENT 201Exploited vulnerabilityHIGH CONFIDENCESourced
CVE-2026-73570 added to CISA KEV: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. </p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-73570" target="_blank">CVE-2026-73570</a> Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability</li> </ul> <p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p> <p><a href="https://www.cisa.gov/news-events/directi…
Last evidence update
21 AUG 2026 · 12:00 UTC
Source count
3
Status
high confidence
GovernmentCVE-2026-73570
Preceded by
Weak signals the observatory recorded before this incident became visible.
Observation history
How this record has evolved as evidence accumulated.
22 AUG · 05:14 UTC
Initial report
22 AUG · 05:14 UTC
Second independent source
22 AUG · 05:14 UTC
Summary updated from new evidence
23 AUG · 05:14 UTC
Second independent source
23 AUG · 05:14 UTC
Confidence upgraded
23 AUG · 05:14 UTC
Status changed
Evidence