CVE-2026-73570: Synacor Zimbra Collaboration Suite (ZCS)
Zimbraコラボレーションスイート(ZCS)には、OSコマンドのインジェクション脆弱性が含まれているため、未認証の攻撃者は、Zimbraユーザーとして任意のオペレーティングシステムのコマンドの実行につながる可能性がある特別に作られたSMTPリクエストを送信できます。
CISA (English)
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- ベンダー
- Synacor
- 製品
- Zimbra Collaboration Suite (ZCS)
- 脆弱性
- Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- 追加日
- 2026/08/21
- CISA対応期限(米国連邦機関向け)
- 2026/08/24
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-78
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02