CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability. Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
- CISA KEV-listed (remediation due 2026-08-24)
- EPSS 0.5% (43.2% percentile)