Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5431 articles · 195446 vulns · 37/41 feeds (7d)
← Back to list
3.1
CVE-2026-73574PATCHED
Zimbra · Collaboration

CVE-2026-73574: In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Clie

Description

In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.

Affected Products

VendorProductVersions
ZimbraCollaboration0

References

  • https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
  • https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy

Related News (1 articles)

Tier C
VulDB7d ago
CVE-2026-73574 | Zimbra Collaboration up to 10.1.16 Classic Web Client WEB-INF/web.xml Forward servlet fu file inclusion
→ No new info (linked only)
CVSS 3.13.1 LOW
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.1.17
CWECWE-669
PublishedAug 13, 2026
Last enriched7d ago
Trending Score12
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-73570EXPKEV
CVE-2026-73570: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
Trending: 122
MEDIUMCVE-2026-73576
CVE-2026-73576: In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice i
Trending: 8
MEDIUMCVE-2026-73572
CVE-2026-73572: In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Cla
Trending: 8
LOWCVE-2026-73575
CVE-2026-73575: In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange W
Trending: 7
LOWCVE-2026-73571
CVE-2026-73571: An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 13, 2026
Discovered by ZDM
Aug 13, 2026
Patch Available
Aug 13, 2026