THREATOPS
THREAT OPSCVEs › CVE-2026-73570

CVE-2026-73570 — Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

CISA KEVExploited: confirmedSynacor

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Vulnerability details

Related reporting