What is CVE-2026-73570?
An OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) allows an unauthenticated attacker to execute arbitrary operating system commands as the Zimbra user by sending specially crafted SMTP requests. This could lead to full compromise of the email server, so ZCS administrators should immediately apply the security update.
Azərbaycanca: Zimbra Collaboration Suite (ZCS)-da autentifikasiya olunmamış hücumçunun xüsusi hazırlanmış SMTP sorğuları vasitəsilə ixtiyari əməliyyat sistemi əmrlərini Zimbra istifadəçisi kimi icra etməsinə imkan verən OS command injection zəifliyi aşkarlanıb. Bu, e-poçt serverinin tam ələ keçirilməsinə səbəb ola bilər, ona görə də ZCS administratorları dərhal təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What type of attack does vulnerability CVE-2026-73570 enable in Zimbra Collaboration Suite?
It enables an OS command injection attack, allowing an unauthenticated attacker to execute arbitrary operating system commands as the Zimbra user via specially crafted SMTP requests.
What is the potential outcome of successfully exploiting this vulnerability?
It could lead to a full compromise of the email server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.