Skip to content
COOEY

EXPOSURES › CVE-2026-73570

CVE-2026-73570

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-73570 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

An unauthenticated attacker can execute arbitrary OS commands via crafted SMTP requests in Zimbra Collaboration Suite due to an OS command injection flaw.

This OS command injection vulnerability allows remote code execution without authentication, enabling attackers to compromise mail servers and pivot to other systems. DIB organizations must ensure Zimbra is patched immediately and monitor for exploitation attempts, as this flaw is actively exploited in the wild and represents a severe compliance risk under NIST 800-171 for unpatched critical vulnerabilities.

Shame score — The vulnerability is actively exploited in the wild, allowing unauthenticated remote code execution, and reflects a chronic failure to patch critical flaws in a widely deployed platform.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.