CVE-2026-73570

8.9

Zimbra · Collaboration

Zimbra Collaboration (ZCS) is susceptible to remote code execution due to improper neutralization of OS commands.

Executive summary

A remote code execution vulnerability in Zimbra Collaboration allows unauthenticated attackers to gain full system control.

Vulnerability

The software fails to properly neutralize special elements used in OS commands (CWE-78), allowing for OS command injection. This vulnerability is remotely exploitable without the need for authentication.

Business impact

Successful exploitation grants an attacker the ability to execute arbitrary commands with the privileges of the Zimbra service, likely leading to total system compromise and data exfiltration. The CVSS score of 8.9 highlights the critical nature of this vulnerability for internet-facing mail servers.

Remediation

Immediate Action: Update Zimbra Collaboration to version 10.1.20 or later immediately.

Proactive Monitoring: Inspect server logs for unusual command execution patterns or unauthorized files created within the web application directory.

Compensating Controls: Ensure the Zimbra server is behind a robust firewall and use a WAF to filter malicious traffic that attempts to inject OS commands.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the remote and unauthenticated nature of this vulnerability, immediate patching is required. Organizations should treat this as a critical priority, especially for ZCS instances exposed to the public internet.

More Zimbra CVEs