
[CIVN-2026-0438] Multiple Vulnerabilities in Zimbra
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Zimbra
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Zimbra Collaboration Suite (ZCS) version prior to 10.1.20.
Overview
Multiple vulnerabilities have been reported in Zimbra Collaboration Suite (ZCS) which could allow an attacker to bypass mail forwarding restrictions, bypass access-control or authorization restrictions, or execute arbitrary operating system commands on the targeted system.
Target Audience:
All end-user organizations and individuals using Zimbra.
Risk Assessment:
High risk of mail forwarding restriction bypass, access-control or authorization bypass and arbitrary command execution.
Impact Assessment:
Potential for email exfiltration, access-control or authorization bypass and arbitrary command execution.
Description
Zimbra is an open-source email and collaboration platform that provides services such as email, calendaring, contacts, and file sharing.
Multiple vulnerabilities have been reported in Zimbra due to improper access controls, authorization weaknesses, and improper input validation in the SNMP monitoring component. An attacker could exploit these vulnerabilities to bypass mail forwarding restrictions, bypass access-control or authorization restrictions, or exfiltrate emails. An unauthenticated attacker could also exploit the SNMP monitoring vulnerability, when the optional zimbra-snmp package is installed and SNMP notifications are enabled, to execute arbitrary operating system commands on the targeted system.
Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate emails, bypass access-control or authorization restrictions, or execute arbitrary operating system commands on the targeted system.
Note – CVE-2026-73570 is being actively exploited in the wild.
Solution
Apply appropriate updates as mentioned by the vendor:
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
Vendor Information
Zimbra
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
References
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
CVE Name
CVE-2026-73570
CVE-2026-50055
CVE-2026-10631
CVE-2026-50054
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqZjRsACgkQ3jCgcSdc
ys/Ntg//YJjP/+cEaBtCWUot+hsx0CrhB1NtJ46Js6c446Z9nw7zhd2CPtykYyl0
l4kctH8uGDdnnIYAcJhO1ophm8Qf8Hs23DVJ0iwJje9wBgQtin5rrBhmUCpgUyeT
0ZEL7jXe8SnoRrTp1kg1kJ1AUjEHSStIEoCLsq802ujDxI32h67kTZpFs4XodGAD
4R5C9UrYh3aNRNW7ENoril4EZx86TH3iy1H4EHlbyYQuFFbgFFoNyDYAVUnOPscA
WncoQsBlXtT91JJkw55CBU+2Lfb4J52uZKwuWY+wAaSJiD4WRf0D809BZlVbSvGl
uSuRleAqFkNPCUIdkg+j78r72bQp1sGcH4EcbVaB5M40eeXwDfRdH8lSRhcUdI8x
XEDE1RKt1twp3URX/0Qk6IuKGHxR4dNJmMvK3zA510nxq+RERHfZ9cPDTQEOToAo
w8jY3tqXR55zPPVM4tQCKhPE24t01Y1hzLOf2VcJET1T5RTBSTeViL5ryLhvECtq
xgOMY/ugazApRCdNFZ07Ukfqupfo3CgDVBLFVi/lwIAo0nYsQ1Y7AS/Ph8qINXyG
pdQln28+aGDqnoM4E/sRj5o6ct674dSZ7tbQMz6INe76mDBfYpO5Bdl+gO1m12OQ
78iinwjewRvb7fBxvY8JSLMA2GLAKrkUg7vLgCqhnKboZpzW86k=
=EySS
—–END PGP SIGNATURE—–


