PatchSiren cyber security CVE debrief
CVE-2026-73572 Zimbra CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:19:06.287Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. CVE-2026-73572 is a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) before 10.1.17. The vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information. Organizations using Zimbra Collaboration (ZCS) versions prior to 10.1.17 should be aware of this vulnerability and take necessary precautions.
- Vendor
- Zimbra
- Product
- Collaboration
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-08-21
Who should care
Organizations using Zimbra Collaboration (ZCS) versions prior to 10.1.17 should be aware of this vulnerability and take necessary precautions. IT administrators, security teams, and users of Zimbra Collaboration (ZCS) are advised to review the CVE record and take appropriate actions to mitigate the risk.
Technical summary
CVE-2026-73572 is a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) before 10.1.17. The vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.
Defensive priority
Medium-priority defensive actions are recommended due to the CVSS score of 6.1 and the potential for unauthorized actions.
Recommended defensive actions
- Inventory and verify Zimbra Collaboration (ZCS) versions to identify potential exposure
- Implement compensating controls such as input validation and content filtering for email attachments
- Monitor for suspicious activity and unauthorized actions within the Zimbra environment
- Apply patches or updates as available from the vendor
- Educate users about safe browsing practices and the risks of clicking on suspicious links or previewing malicious attachments
Evidence notes
The CVE-2026-73572 record indicates a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) before 10.1.17. The vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. However, detailed information about affected versions, vendor advisories, or patch availability is limited in the provided source corpus.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:19:06.287Z and has not been modified since then.