What is CVE-2026-73572?
A stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) before version 10.1.17 allows attackers to inject malicious scripts via a crafted email attachment in the Zimbra Classic Web Client. Immediate patching is required to prevent exploitation of this issue.
Azərbaycanca: Bu boşluq Zimbra Collaboration Suite (ZCS) 10.1.17-dən əvvəlki versiyaların Zimbra Classic Web Client-inə təsir edir. Təcavüzkar xüsusi hazırlanmış e-poçt əlavəsi vasitəsilə stored cross-site scripting (XSS) hücumu həyata keçirə bilər, buna görə də sistem administratorları dərhal təhlükəsizlik yamasını tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which component of the product is affected by CVE-2026-73572?
This vulnerability affects the Zimbra Classic Web Client component of Zimbra Collaboration Suite.
What immediate measure is recommended to prevent exploitation of CVE-2026-73572?
System administrators must apply the security patch immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.