Zimbra
Vulnerabilities, patches, and vendor advisories affecting Zimbra Collaboration Suite — the Classic Web Client, Modern UI, and mailboxd server components — plus the operational impact of Zimbra patch cycles on the organizations still self-hosting webmail.

270 Zimbra Servers Breached as KEV Deadline Expires
Attackers have compromised 270+ Zimbra ZCS servers via CVE-2026-73570 SNMP RCE. CISA's Aug 24 KEV patch deadline is past; upgrade to ZCS 10.1.20 now.

Zimbra SNMP RCE Now Exploited in the Wild
CVE-2026-73570, a CVSS 8.9 command injection in Zimbra ZCS, is under active exploitation per CERT Polska. Patch to 10.1.20 or later immediately.

Void Blizzard Exploits Zimbra Flaw for Email Theft
CISA warns Russian state-sponsored Void Blizzard (Laundry Bear) is combining phishing with a patched Zimbra zero-click flaw to steal email from targeted organizations.

Zimbra 10.1.20 patches nine, SNMP injection at the top
Zimbra 10.1.20 fixes nine vulnerabilities including an SNMP command injection when notifications are enabled. Patch if you self-host — CVEs pending.

Zimbra ships 10.1.19; Google TAG reported the XSS
Zimbra 10.1.19 patches a stored XSS in the Classic Web Client. No CVE yet, no confirmed exploitation — Google TAG reported it, which is the reason to patch now.