Skip to content
Threat Feed
critical threat exploited

Critical Vulnerabilities in Synacor Zimbra Collaboration

Synacor Zimbra Collaboration versions prior to 10.1.20 are vulnerable to multiple flaws, including actively exploited RCE (CVE-2026-73570), SSRF, and XSS, posing a high risk of unauthorized system access.

CVE search metadata

CVE search record: CVE-2026-73570. Severity: high. CVSS: 8.9. EPSS: 0.54%. KEV: no. Product: Zimbra Collaboration. Brief: Critical Vulnerabilities in Synacor Zimbra Collaboration. Brief link: https://feed.craftedsignal.io/briefs/2026-08-zimbra-vulnerabilities/

Security researchers and the French national cybersecurity agency (ANSSI) have disclosed multiple vulnerabilities affecting Synacor Zimbra Collaboration versions prior to 10.1.20. These flaws include remote code execution (RCE), server-side request forgery (SSRF), and cross-site scripting (XSS). Notably, the vulnerability tracked as CVE-2026-73570 is currently being actively exploited in the wild, according to ENISA. Organizations running legacy or unpatched instances of Zimbra Collaboration are at significant risk of total system compromise, data exfiltration, or lateral movement via the exploited services. Patching to version 10.1.20 or later is the only remediation path provided by the vendor.

Impact

Successful exploitation of these vulnerabilities allows unauthenticated or authenticated attackers to execute arbitrary code on the underlying mail server, pivot into internal network infrastructure via SSRF, or conduct session hijacking through XSS. The active exploitation of CVE-2026-73570 significantly increases the risk for organizations with internet-facing Zimbra nodes, potentially leading to widespread account takeovers and infrastructure compromise.

Recommendation

  • Immediately upgrade all instances of Zimbra Collaboration to version 10.1.20 or later to mitigate CVE-2026-73570, CVE-2026-10631, CVE-2026-50054, and CVE-2026-50055.
  • Monitor webserver access logs for anomalous requests to Zimbra endpoints that deviate from established baselines for mail and administrative interface traffic.
  • Audit firewall configurations to ensure that the Zimbra server does not have unnecessary outbound access to internal network segments, limiting the impact of potential SSRF exploitation.
  • Review all post-patch logs for signs of persistence, such as unauthorized service accounts or unexpected web shell files in known Zimbra directories.