[CIVN-2026-0438] Multiple Vulnerabilities in Zimbra

By Published On: September 3, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Zimbra


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Zimbra Collaboration Suite (ZCS) version prior to 10.1.20.

Overview


Multiple vulnerabilities have been reported in Zimbra Collaboration Suite (ZCS) which could allow an attacker to bypass mail forwarding restrictions, bypass access-control or authorization restrictions, or execute arbitrary operating system commands on the targeted system.


Target Audience:

All end-user organizations and individuals using Zimbra.


Risk Assessment:

High risk of mail forwarding restriction bypass, access-control or authorization bypass and arbitrary command execution.


Impact Assessment:

Potential for email exfiltration, access-control or authorization bypass and arbitrary command execution.


Description


Zimbra is an open-source email and collaboration platform that provides services such as email, calendaring, contacts, and file sharing.


Multiple vulnerabilities have been reported in Zimbra due to improper access controls, authorization weaknesses, and improper input validation in the SNMP monitoring component. An attacker could exploit these vulnerabilities to bypass mail forwarding restrictions, bypass access-control or authorization restrictions, or exfiltrate emails. An unauthenticated attacker could also exploit the SNMP monitoring vulnerability, when the optional zimbra-snmp package is installed and SNMP notifications are enabled, to execute arbitrary operating system commands on the targeted system.


Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate emails, bypass access-control or authorization restrictions, or execute arbitrary operating system commands on the targeted system.


Note – CVE-2026-73570 is being actively exploited in the wild.


Solution


Apply appropriate updates as mentioned by the vendor:

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories



Vendor Information


Zimbra

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories


References


 

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories


CVE Name

CVE-2026-73570

CVE-2026-50055

CVE-2026-10631

CVE-2026-50054




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqZjRsACgkQ3jCgcSdc

ys/Ntg//YJjP/+cEaBtCWUot+hsx0CrhB1NtJ46Js6c446Z9nw7zhd2CPtykYyl0

l4kctH8uGDdnnIYAcJhO1ophm8Qf8Hs23DVJ0iwJje9wBgQtin5rrBhmUCpgUyeT

0ZEL7jXe8SnoRrTp1kg1kJ1AUjEHSStIEoCLsq802ujDxI32h67kTZpFs4XodGAD

4R5C9UrYh3aNRNW7ENoril4EZx86TH3iy1H4EHlbyYQuFFbgFFoNyDYAVUnOPscA

WncoQsBlXtT91JJkw55CBU+2Lfb4J52uZKwuWY+wAaSJiD4WRf0D809BZlVbSvGl

uSuRleAqFkNPCUIdkg+j78r72bQp1sGcH4EcbVaB5M40eeXwDfRdH8lSRhcUdI8x

XEDE1RKt1twp3URX/0Qk6IuKGHxR4dNJmMvK3zA510nxq+RERHfZ9cPDTQEOToAo

w8jY3tqXR55zPPVM4tQCKhPE24t01Y1hzLOf2VcJET1T5RTBSTeViL5ryLhvECtq

xgOMY/ugazApRCdNFZ07Ukfqupfo3CgDVBLFVi/lwIAo0nYsQ1Y7AS/Ph8qINXyG

pdQln28+aGDqnoM4E/sRj5o6ct674dSZ7tbQMz6INe76mDBfYpO5Bdl+gO1m12OQ

78iinwjewRvb7fBxvY8JSLMA2GLAKrkUg7vLgCqhnKboZpzW86k=

=EySS

—–END PGP SIGNATURE—–

Share this article