CVE-2026-73570
HIGH(8.9)KEVErhöhtes Risiko
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Beschreibung
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:LIm Rechner öffnenBetroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| synacor | zimbra collaboration suite | < 10.1.20 |
Referenzen
- https://wiki.zimbra.com/wiki/Security_Center(Release Notes)
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories(Vendor Advisory)
- https://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570(US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.