CVE-2026-73575
published 2026-08-13CVE-2026-73575: In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra…
PriorityP413low3.1CVSS 3.1
AVNACHPRNUIRSUCNILAN
EPSS
0.11%
1.6th percentile
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zimbra | collaboration | < 10.1.17 | 10.1.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Zimbra Collaboration up to 10.1.16 Exchange Web Services cross-site request forgery (WID-SEC-2026-1735)
vuldb·2026-08-16·CVSS 3.1
CVE-2026-73575 [LOW] Zimbra Collaboration up to 10.1.16 Exchange Web Services cross-site request forgery (WID-SEC-2026-1735)
A vulnerability was found in Zimbra Collaboration up to 10.1.16. It has been declared as problematic. This vulnerability affects unknown code of the component Exchange Web Services. Such manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2026-73575. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient val
ghsa_unreviewed·2026-08-13
CVE-2026-73575 [LOW] CWE-352 In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient val
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published