Station Brief
BriefenforcementAug 17, 2026

CISA Adds Exploited Flaws to Catalog, Orders Fast Zimbra Patching

CISA added two vulnerabilities to its catalog of actively exploited flaws on August 20, following four on August 18 and one on August 19 [1][2][3]. Federal civilian agencies must prioritize fixing listed CVEs under Binding Operational Directive 26-04 [1]. CISA also directed federal agencies to patch an actively exploited Zimbra Collaboration Suite flaw, CVE-2026-73570, within three days; Zimbra fixed it in version 10.1.20, released July 20, and exploitation can let unauthenticated attackers run code remotely through the SNMP monitoring component [5].

cybersecuritytechaiworldelectricalcryptogrid_ercotsmall_business

Sources

  1. cisa.gov · CISA Adds Two Known Exploited Vulnerabilities to Catalog Aug 20, 2026
  2. cisa.gov · CISA Adds One Known Exploited Vulnerability to Catalog Aug 19, 2026
  3. cisa.gov · CISA Adds Four Known Exploited Vulnerabilities to Catalog Aug 18, 2026
  4. cisa.gov · CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards Aug 20, 2026
  5. bleepingcomputer.com · CISA orders urgent patching of actively exploited Zimbra flaw Aug 24, 2026
  6. cnbc.com · Small UK power generator shut down after cyberattack linked to Iran: Telegraph Aug 23, 2026

This is the neutral brief the press writes once, for everyone, before each reader’s paper adds its own so-what. It links out; it does not republish. 6 articles clustered.

Print your own paper