HIGHVulnerability
Verified
Global

CISA KEV: Synacor Zimbra Collaboration Suite (ZCS) — Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Analysis

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. Added to CISA Known Exploited Vulnerabilities catalog on 2026-08-21. Remediation due: 2026-08-24.

Indicators of Compromise (1)

CVE (1)
CVE-2026-73570
Source Attribution

Originally published by CISA KEV on Aug 21, 2026. Verified by: CISA.

Related Threats