CiberLATAMbywhalemate

CISA adds five critical CVEs to KEV catalog

CISA added CVE-2026-73570 in Zimbra to KEV and set the federal remediation deadline for Aug. 24.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

CISA added a fifth actively exploited vulnerability to its Known Exploited Vulnerabilities catalog, CVE-2026-73570 in Zimbra Collaboration Suite, joining flaws already listed in Apple, Microsoft and VMware. The update brought the total to five covered issues and tightened federal patch deadlines.

Update August 29, 2026: CISA expanded its KEV catalog with a fifth actively exploited vulnerability, CVE-2026-73570 in Zimbra Collaboration Suite, and added new details on technical scope, remediation deadlines and reports of in-the-wild exploitation.

CISA added four actively exploited vulnerabilities on Aug. 18, 2026, one in Apple macOS Screen Sharing, one in Microsoft IKE, one in Microsoft SharePoint and one in VMware vCenter, to its Known Exploited Vulnerabilities catalog. The agency set Aug. 21, 2026, as the remediation deadline for US federal entities in the cases covered by that directive. It later added a fifth flaw, CVE-2026-73570 in Zimbra Collaboration Suite, with a Date Added of Aug. 21, 2026 and a Due Date of Aug. 24, 2026.

What vulnerabilities were added to KEV?

CISA added CVE-2026-65400, CVE-2026-33824, CVE-2026-55040 and CVE-2026-59310, all reported as actively exploited, and later added CVE-2026-73570 for Zimbra Collaboration Suite. According to the technical coverage compiled on each issue, the list includes an authentication bypass in macOS Screen Sharing, a double free flaw in Microsoft Internet Key Exchange Service Extensions, a vulnerability in Microsoft SharePoint, a critical path traversal issue in Broadcom VMware vCenter Syslog Server and a command injection in Zimbra.

For CVE-2026-33824, Ciberplaneta reported a critical double-free vulnerability that allows remote code execution without prior authentication. Penligent also described it as a pre-authentication remote code execution flaw in Windows IKE Extensions and confirmed that CISA added it to KEV on Aug. 18, 2026, as an actively exploited vulnerability.

On CVE-2026-59310, f4n6 said it is a critical path traversal vulnerability with a CVSS score of 9.8 in Broadcom VMware vCenter Syslog Server. SecurityWeek added that CISA placed that flaw, along with the Microsoft and Apple issues, in the KEV catalog and urged immediate patching.

The weekly update also included CVE-2026-73570, which CISA added to KEV on Aug. 21, 2026. FireCompass included it among nine vulnerabilities added by the agency between Aug. 17 and Aug. 23, 2026, all confirmed as exploited in the wild.

What is known about the Apple case?

CVE-2026-65400 was treated as a critical authentication bypass flaw in macOS Screen Sharing, with a CVSS score of 9.8 and active exploitation, and CISA added it to KEV on Aug. 18, 2026. Tanium also noted that the CVSS score was reassessed to 9.8 on Aug. 14 and that the federal remediation deadline was set for Aug. 21.

The Canadian Centre for Cyber Security advisory specified patch coverage for macOS Tahoe 26.x before 26.6.1, macOS Sequoia 15.x before 15.7.9 and macOS Sonoma 14.x before 14.8.9. That same Canadian alert confirmed that CISA added CVE-2026-65400 to its KEV database.

What changes with Zimbra Collaboration Suite?

CVE-2026-73570 affects Zimbra versions earlier than 10.1.20 only when the optional zimbra-snmp package is installed and SNMP notifications are enabled, and it can be exploited with manipulated SMTP messages to run commands as the zimbra user. CISA added it to KEV on Aug. 21, 2026, and set Aug. 24, 2026 as the deadline for US federal agencies to remediate it.

CERT Polska confirmed in-the-wild exploitation on Aug. 17, 2026, before CISA’s inclusion. NVD said the technical impact is limited to servers with zimbra-snmp installed and SNMP notifications enabled, while RunZero specified that the issue affects versions earlier than 10.1.20 when snmp_notify is configured.

Moncloa reported Zimbra’s addition to CISA’s KEV with warnings of active exploitation, and Devel Group said exploitation in the wild was also confirmed. HelpNetSecurity later said multiple unpatched servers are being compromised through specially crafted SMTP requests aimed at the SNMP component.

SC Media added that Russia-linked APT groups are targeting affected Zimbra instances tied to CVE-2026-73570, with victims in government agencies, universities and state entities in Brazil and Argentina. That coverage gives the issue a direct regional impact for Latin America, beyond the initial global context.

What did regional authorities say?

Brazil’s Institutional Security Office, through CTIR.GOV, issued alert 68/2026 about a vulnerability in Microsoft Internet Key Exchange Service Extensions. In that notice, the agency reminded readers that inclusion in the KEV catalog is based on reliable evidence of active exploitation and on the availability of vendor fixes.

That regional warning serves as an operational reference for teams in Latin America managing environments with Microsoft, Apple, VMware or Zimbra. The technical material cited by CISA and by specialized media places the five flaws in widely used products that should be treated as patch priorities.

HackerStorm said that for CVE-2026-73570, CISA requires updating Zimbra to 10.1.20 or disabling zimbra-snmp within a maximum of 24 hours. The same regulatory coverage said that for CVE-2026-59310 in VMware vCenter Server, the deadline is 72 hours and recommended strict access controls on management interfaces.

Sources

View all