CVE-2026-73570: Synacor Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) 包含一個 OS 命令注射漏洞,可能允許未經認證的攻擊者傳送專門設計的 SMTP 請求,這可能會導致作為 Zimbra 使用者執行自願作業系統命令。
CISA (English)
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- 廠商
- Synacor
- 產品
- Zimbra Collaboration Suite (ZCS)
- 漏洞
- Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- 加入日期
- 2026年8月21日
- CISA 修補期限(美國聯邦機關)
- 2026年8月24日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-78
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02