PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73572 Zimbra CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:19:06.287Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. CVE-2026-73572 is a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) before 10.1.17. The vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information. Organizations using Zimbra Collaboration (ZCS) versions prior to 10.1.17 should be aware of this vulnerability and take necessary precautions.

Vendor
Zimbra
Product
Collaboration
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-08-21
Advisory published
2026-08-13
Advisory updated
2026-08-21

Who should care

Organizations using Zimbra Collaboration (ZCS) versions prior to 10.1.17 should be aware of this vulnerability and take necessary precautions. IT administrators, security teams, and users of Zimbra Collaboration (ZCS) are advised to review the CVE record and take appropriate actions to mitigate the risk.

Technical summary

CVE-2026-73572 is a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) before 10.1.17. The vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.

Defensive priority

Medium-priority defensive actions are recommended due to the CVSS score of 6.1 and the potential for unauthorized actions.

Recommended defensive actions

  • Inventory and verify Zimbra Collaboration (ZCS) versions to identify potential exposure
  • Implement compensating controls such as input validation and content filtering for email attachments
  • Monitor for suspicious activity and unauthorized actions within the Zimbra environment
  • Apply patches or updates as available from the vendor
  • Educate users about safe browsing practices and the risks of clicking on suspicious links or previewing malicious attachments

Evidence notes

The CVE-2026-73572 record indicates a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) before 10.1.17. The vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. However, detailed information about affected versions, vendor advisories, or patch availability is limited in the provided source corpus.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:19:06.287Z and has not been modified since then.