CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Summary
A critical OS command injection vulnerability, CVE-2026-73570, has been identified in Synacor Zimbra Collaboration Suite (ZCS). Unauthenticated attackers can exploit this by sending crafted SMTP requests to execute arbitrary OS commands as the Zimbra user.
IFF Assessment
The vulnerability allows unauthenticated attackers to execute arbitrary commands on the system, posing a significant risk to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: August 24, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in Zimbra Collaboration Suite presents a high-risk attack vector. Defenders must prioritize applying vendor-provided mitigations immediately, especially for internet-facing instances. It highlights the ongoing threat of command injection flaws in widely used collaboration platforms.