CVE-2026-73570CISA KEVEPSS p96.0%

CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

Synacor / Zimbra Collaboration Suite (ZCS)

Description

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Scoring

CVSS 8.9 ()
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
EPSS11.95% probability of exploitation · percentile 96.0% · 2026-10-05T12:00:23Z
Last modified2026-08-24

CISA KEV entry

Added to KEV: 2026-08-21

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.