AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73572

MEDIUM · CVSS 6.1 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Zimbra Collaboration Suite prior to version 10.1.17 is vulnerable to a stored cross-site scripting (XSS) flaw in the Classic Web Client, stemming from inadequate sanitization of attachment content during inline previews. This vulnerability allows attackers to execute arbitrary JavaScript in the victim's browser, potentially enabling unauthorized actions and data exfiltration. Organizations using affected versions of Zimbra should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73572
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%
Java

Original NVD Description

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.