CVE Tools

Zimbra Collaboration Suite

108 CVEs tracked. 19 of them are in CISA KEV.

This hub aggregates every CVE we track for Zimbra Collaboration Suite, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Zimbra Collaboration Suite CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Zimbra Collaboration Suite CVEs per month
MonthCVEs
2024-102
2024-119
2024-121
2025-010
2025-022
2025-032
2025-041
2025-051
2025-061
2025-072
2025-080
2025-090
2025-101
2025-110
2025-121
2026-011
2026-020
2026-036
2026-040
2026-050
2026-060
2026-070
2026-087
2026-090

Severity

How the 108 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1211%
  • High2826%
  • Medium6459%
  • Low44%

Latest CVEs

The 15 most recently published vulnerabilities affecting Zimbra Collaboration Suite.

  1. CVE-2026-73576In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecur...6.3
  2. CVE-2026-73575In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient ...3.1
  3. CVE-2026-73574In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated...3.1
  4. CVE-2026-73573In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An a...3.1
  5. CVE-2026-73572In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment conte...6.1
  6. CVE-2026-73571An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacke...3.1
  7. CVE-2026-73570A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sani...8.9
  8. CVE-2026-33373An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens witho...8.8
  9. CVE-2026-33370An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient sanitization of spe...6.1
  10. CVE-2026-33371An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handl...4.3
  11. CVE-2026-33368Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails to properly sanit...6.1
  12. CVE-2026-33369Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-suppli...4.3
  13. CVE-2026-33372An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF tokens. The applic...5.4
  14. CVE-2025-66376Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.7.2
  15. CVE-2025-68645A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestF...8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store