CVE-2026-73570 - Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- Severity
- critical
- Product
- Synacor Zimbra Collaboration Suite (ZCS)
- Published
- 2026-08-21
- EPSS
- 0.717
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2026-73570&type=repositories
- https://nvd.nist.gov/vuln/detail/CVE-2026-73570
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.