EXPOSURES › CVE-2026-73570
CVE-2026-73570
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated attacker can execute arbitrary OS commands via crafted SMTP requests in Zimbra Collaboration Suite due to an OS command injection flaw.
This OS command injection vulnerability allows remote code execution without authentication, enabling attackers to compromise mail servers and pivot to other systems. DIB organizations must ensure Zimbra is patched immediately and monitor for exploitation attempts, as this flaw is actively exploited in the wild and represents a severe compliance risk under NIST 800-171 for unpatched critical vulnerabilities.
Shame score — The vulnerability is actively exploited in the wild, allowing unauthenticated remote code execution, and reflects a chronic failure to patch critical flaws in a widely deployed platform.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.