CVE-2026-73570: Synacor Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) bevat een OS commando injectie kwetsbaarheid die een ongeauthenticeerde aanvaller in staat zou kunnen stellen om speciaal vervaardigde SMTP verzoeken te verzenden die kunnen resulteren in de uitvoering van willekeurige besturingssysteem commando's als de Zimbra gebruiker.
CISA (English)
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- Leverancier
- Synacor
- Product
- Zimbra Collaboration Suite (ZCS)
- Kwetsbaarheid
- Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Toegevoegd op
- 21 aug 2026
- CISA-termijn (Amerikaanse federale instanties)
- 24 aug 2026
- Bekend gebruik in ransomwarecampagnes
- Onbekend
- Zwakte (CWE)
- CWE-78
Referenties
Deze site vat de CISA-catalogus alleen ter informatie samen. Het is geen beveiligingsadvies – volg de richtlijnen van uw leverancier en officiële adviezen.
Laatst bijgewerkt: · Catalogusversie 2026.10.02