
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73572 is a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) Classic Web Client affecting all versions before 10.1.17. The flaw stems from insufficient sanitization of specific attachment content during inline preview, allowing an unauthenticated attacker to send a crafted email whose malicious attachment executes arbitrary JavaScript in the victim's browser when previewed. It was published on August 13, 2026, with a patch available in version 10.1.17. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Zimbra Security Advisories).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. The Zimbra Classic Web Client fails to adequately sanitize attachment content before rendering it inline in the browser, allowing embedded JavaScript to be executed in the victim's session context. Exploitation requires no authentication or special privileges on the attacker's part, but does require the victim to preview the malicious attachment within the web client. The attack vector is network-based with low complexity, and the scope is changed (S:C), meaning the injected script can affect resources beyond the vulnerable component itself (GitHub Advisory, Zimbra Security Advisories).
Successful exploitation allows an attacker to execute arbitrary JavaScript within the victim's authenticated browser session, enabling session hijacking, credential theft, unauthorized actions performed on behalf of the victim, and potential exfiltration of sensitive email data or other information accessible within the Zimbra web client. The changed scope means the impact extends beyond the immediate application context. Availability is not directly impacted, but confidentiality and integrity are both partially compromised (GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable, as it requires user interaction (victim must preview the attachment). The EPSS score is approximately 0.155%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
The primary remediation is to upgrade Zimbra Collaboration (ZCS) to version 10.1.17 or later, which contains the fix for this vulnerability (Zimbra Security Advisories, GitHub Advisory). As an interim workaround, administrators should educate users to avoid previewing attachments from untrusted or unknown senders, and consider disabling inline attachment preview functionality if the Zimbra configuration permits. Implementing email gateway filtering to detect and quarantine suspicious attachments can also reduce exposure until patching is complete.
The vulnerability was noted by automated CVE tracking services and threat intelligence platforms shortly after disclosure on August 13, 2026, including VulDB, CVEFeed, and Offseq Radar. Zimbra published an update to their Security Advisories wiki page and released version 10.1.17 to address the issue (Zimbra Security Advisories). No significant independent researcher commentary or major media coverage has been identified at this time, consistent with the moderate severity rating and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."