CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

Summary

A critical OS command injection vulnerability, CVE-2026-73570, has been identified in Synacor Zimbra Collaboration Suite (ZCS). Unauthenticated attackers can exploit this by sending crafted SMTP requests to execute arbitrary OS commands as the Zimbra user.

IFF Assessment

FOE

The vulnerability allows unauthenticated attackers to execute arbitrary commands on the system, posing a significant risk to defenders.

Severity

8.9 High

CISA KEV: Listed as actively exploited. Federal patch due: August 24, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in Zimbra Collaboration Suite presents a high-risk attack vector. Defenders must prioritize applying vendor-provided mitigations immediately, especially for internet-facing instances. It highlights the ongoing threat of command injection flaws in widely used collaboration platforms.

Read Full Story →