CVE-2026-73570: Synacor Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- Vendor
- Synacor
- Product
- Zimbra Collaboration Suite (ZCS)
- Vulnerability
- Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Date added
- Aug 21, 2026
- CISA due date (U.S. federal agencies)
- Aug 24, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-78
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02