CVE-2026-73570: Synacor Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS)에는 OS 명령 주입 취약점이 포함되어 있으며 특별히 제작 된 SMTP 요청을 보낼 수 없으므로 Zimbra 사용자로서 임의 운영 체제 명령을 실행할 수 있습니다.
CISA (English)
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- 공급업체
- Synacor
- 제품
- Zimbra Collaboration Suite (ZCS)
- 취약점
- Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- 추가일
- 2026. 8. 21.
- CISA 조치 기한(미국 연방기관)
- 2026. 8. 24.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-78
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02