The U.S. Cybersecurity and Infrastructure Security Agency (CISA) orders federal agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The flaw is identified as CVE-2026-73570, and both outlets report it is being used in attacks in the wild.

CISA’s directive emphasizes a shrinking remediation window for organizations that use Zimbra. Dark Reading and Bleeping Computer both describe the impact as severe, stating the vulnerability can enable full takeover of a user’s communications. While the sources focus on CISA’s fast deadline and the urgency of patching, their common framing centers on the risk to affected email and collaboration environments and the need to apply updates promptly to reduce exposure.