Executive brief
Zimbra Collaboration Suite is widely deployed email and collaboration software. An unauthenticated attacker can craft malicious SMTP messages to execute arbitrary system commands on the mail server with the privileges of the Zimbra service account. This vulnerability enables complete server compromise, data theft, and lateral movement within organizational networks.
Technical details
This is an OS command injection vulnerability in Zimbra Collaboration Suite's SMTP message processing component. An unauthenticated remote attacker can send specially crafted SMTP requests that inject operating system commands, leading to arbitrary command execution under the Zimbra service user context. The vulnerability requires no authentication and is reachable via the network on standard SMTP ports. Successful exploitation grants the attacker the ability to execute arbitrary system commands, potentially achieving full server compromise. The vulnerability is known to be actively exploited in the wild as of the disclosure date.
Affected products
- Zimbra Collaboration Suite <UNKNOWN>
Timeline
- 2026-08-21: disclosed
- 2026-08-21: exploited: actively exploited in the wild at time of disclosure