CISA's binding directive gives federal agencies until August 28 to patch CVE-2026-73570, a Zimbra Collaboration Suite flaw that hands an unauthenticated attacker full takeover of a user's mailbox. The advisory does not say how the exploitation was first observed, and it does not need to: Zimbra sits on the internet by design, every instance is reachable the moment the CVE goes public, and the agency's three-day window is a statement about attacker speed, not patch complexity. Dark Reading's framing of "shrinking patch windows" is the vendor-adjacent read. The operational read is that CISA no longer expects a week's grace between disclosure and exploitation at internet scale.
The same week Red Hat shipped patches for a critical Keycloak flaw letting an unauthenticated attacker hijack any account through the password-reset flow, a control failure with the same shape: identity infrastructure exposed to the open internet, patched reactively. Neither CVE bulletin says which came first, exploitation or disclosure. For a CISO with Zimbra or Keycloak in the environment, the only defensible move by August 28 is patch confirmation, not risk acceptance pending "further guidance."