← All Briefings
Briefings


CISA Gives Three Days To Patch Zimbra Bug Under Live Attack

CISA's binding directive gives federal agencies until August 28 to patch CVE-2026-73570, a Zimbra Collaboration Suite flaw that hands an unauthenticated attacker full takeover of a user's mailbox. The advisory does not say how the exploitation was first observed, and it does not need to: Zimbra sits on the internet by design, every instance is reachable the moment the CVE goes public, and the agency's three-day window is a statement about attacker speed, not patch complexity. Dark Reading's framing of "shrinking patch windows" is the vendor-adjacent read. The operational read is that CISA no longer expects a week's grace between disclosure and exploitation at internet scale.

The same week Red Hat shipped patches for a critical Keycloak flaw letting an unauthenticated attacker hijack any account through the password-reset flow, a control failure with the same shape: identity infrastructure exposed to the open internet, patched reactively. Neither CVE bulletin says which came first, exploitation or disclosure. For a CISO with Zimbra or Keycloak in the environment, the only defensible move by August 28 is patch confirmation, not risk acceptance pending "further guidance."

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.