← Back to overview

Zimbra Collaboration Suite (ZCS) contains a critical OS command injection vulnerability tracked as CVE-2026-73570. An unauthenticated attacker can exploit this flaw by sending specially crafted SMTP requests, potentially resulting in arbitrary operating system command execution as the Zimbra user. The vulnerability requires no authentication, making it especially dangerous in internet-exposed deployments. CISA has flagged this under BOD 26-04, which prioritizes security updates based on risk. Zimbra has released a patch in version 10.1.20 to address the issue. Organizations are urged to apply the patch immediately and review Zimbra Security Advisories for further guidance. Forensics triage requirements have also been outlined by CISA for affected systems. The vulnerability is listed in the NVD and carries a high criticality rating.

Affected products

  • Zimbra Collaboration Suite (ZCS) 10.1.20 and prior

Related CVE's

  • CVE-2026-73570

Categories

  • Email & Messaging
  • Enterprise Applications
  • Zero-Day Vulnerabilities