THREAT OPS › Threat News › [NVD] CVE-2026-73574 (LOW 3.1) — In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially a
[NVD] CVE-2026-73574 (LOW 3.1) — In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially a
CVE-2026-73574 CVSS: 3.1 LOW Published: 2026-08-13T16:19:06.593
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, suc
Indicators of compromise
- CVE-2026-73574cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73574