CVE-2026-73576
- EPSS 0.19%
- Veröffentlicht 13.08.2026 15:26:20
- Zuletzt bearbeitet 13.08.2026 16:19:06
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient e...
CVE-2026-73575
- EPSS 0.11%
- Veröffentlicht 13.08.2026 15:24:53
- Zuletzt bearbeitet 13.08.2026 16:19:06
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can ...
CVE-2026-73574
- EPSS 0.2%
- Veröffentlicht 13.08.2026 15:23:55
- Zuletzt bearbeitet 13.08.2026 16:19:06
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying...
CVE-2026-73573
- EPSS 0.25%
- Veröffentlicht 13.08.2026 15:22:21
- Zuletzt bearbeitet 13.08.2026 16:19:06
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability ...
CVE-2026-73572
- EPSS 0.16%
- Veröffentlicht 13.08.2026 15:21:28
- Zuletzt bearbeitet 13.08.2026 16:19:06
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a craf...
CVE-2026-73571
- EPSS 0.17%
- Veröffentlicht 13.08.2026 15:20:39
- Zuletzt bearbeitet 13.08.2026 16:19:06
An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to imperso...
CVE-2026-73570
- EPSS 0.54%
- Veröffentlicht 13.08.2026 15:19:42
- Zuletzt bearbeitet 14.08.2026 05:17:00
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification ...
CVE-2026-33373
- EPSS 0.2%
- Veröffentlicht 30.03.2026 15:16:29
- Zuletzt bearbeitet 07.04.2026 18:50:47
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state trans...
CVE-2026-33372
- EPSS 0.14%
- Veröffentlicht 20.03.2026 14:16:16
- Zuletzt bearbeitet 01.04.2026 15:32:50
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF tokens. The application accepts CSRF tokens supplied within the request...
CVE-2026-33371
- EPSS 0.23%
- Veröffentlicht 20.03.2026 14:16:16
- Zuletzt bearbeitet 01.04.2026 15:35:47
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submi...