Security
Loading…

CVE-2026-73570

HIGHCVSS 8.9Known Exploited
Description

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Timeline
Published:August 13th, 2026 4:19 PM
Last modified:August 24th, 2026 1:19 PM
Added to KEV:August 21st, 2026
CVSS Scoring

CVSS v3: 8.9 (HIGH)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Affected Software
From NVD CPE configuration data

Vendors

synacor

Products

zimbra_collaboration_suite
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute