🚨SEVERITY: HIGH — CVSS 8.9Security Advisory
TL;DR 📌
- Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- Highest CVSS: 8.9 (High).
- Listed in CISA KEV (2026-08-21) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-73570.
What it is
CVE-2026-73570 is an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS), reported by Synacor. The flaw sits in how ZCS handles SMTP requests: a specially crafted SMTP request can trigger execution of arbitrary operating system commands, running as the Zimbra user.