Our automated tracking framework flagged that CISA added CVE-2026-73570 (Synacor Zimbra Collaboration Suite (ZCS)) to the Known Exploited Vulnerabilities (KEV) catalog on August 23, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.

What CISA Reported

CISA describes the flaw as follows: “Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.”

Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-73570 by August 24, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.

The Details

CVE CVE-2026-73570
Vendor / product Synacor Zimbra Collaboration Suite (ZCS)
Vulnerability Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
CVSS base score 8.9
Added to KEV August 21, 2026
Days public before listing (NVD → KEV lag) 8
Federal patch deadline August 24, 2026
Known ransomware use No

How This Compares to Synacor’s Track Record

This one was public for just 8 days before CISA confirmed exploitation — faster than Synacor’s 112-day median, meaning attackers moved unusually quickly.

Synacor in the CISA KEV catalog Value
Tracked KEV entries 19
Median lag (public → KEV listing) 112 days
0-day rate (exploited at or before disclosure) 11%
Entries tied to known ransomware campaigns 5

For perspective, the median across all 1674 tracked KEV entries is 266 days — Synacor’s exploited vulnerabilities are flagged faster than the catalog average.

Other Recent Synacor KEV Additions

The most recent Synacor vulnerabilities CISA has confirmed as actively exploited, from our tracker:

CVE Product Added to KEV Lag (days) Ransomware
CVE-2025-48700 Zimbra Collaboration Suite (ZCS) April 20, 2026 301 No
CVE-2025-66376 Zimbra Collaboration Suite (ZCS) March 18, 2026 72 No
CVE-2020-7796 Zimbra Collaboration Suite February 17, 2026 2191 No
CVE-2025-68645 Zimbra Collaboration Suite (ZCS) January 22, 2026 31 No
CVE-2025-27915 Zimbra Collaboration Suite (ZCS) October 7, 2025 209 No

What This Means for Defenders

CISA has added CVE-2026-73570, an OS Command Injection vulnerability in Synacor Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities (KEV) catalog. It has a CVSS base score of 8.9. The federal patch deadline is tight: August 24, 2026, just three days after its KEV listing on August 21, 2026. Patching is critical for all organizations using Zimbra ZCS, especially those with public-facing instances.

This vulnerability was public for 8 days before its addition to the KEV, indicating rapid exploitation by threat actors. If you can’t patch before the deadline, restrict access to ZCS instances immediately. Also, enhance monitoring for anomalous activity from or targeting ZCS servers, and deploy web application firewalls (WAFs) to block malicious requests. While ransomware use isn’t confirmed for CVE-2026-73570, OS command injection vulnerabilities are frequently used for initial access and privilege escalation.

Related Coverage

How We Track This

This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.