Z
Zimbra
Security Risk Profile
35
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 114 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 10, 2008 to present
114
Total CVEs
34
Critical+High
19
Exploited
30
Unpatched
Threat Assessment
Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
30
Critical/High
Risk Level
35/100
low
⚠️ 19 Active Exploits⚡ 7 Zero-Days🆕 1Fresh (<7d)📈 8 in Last 30 Days
Severity Distribution
Critical
11High
23Medium
67Low
5Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
10Age Distribution
Common Weaknesses (CWE)
1
XSS
53
2
CSRF
11
3
SSRF
6
4
Path Traversal
5
5
Command Injection
5
Most Affected Products
1. Zimbra Collaboration1560
2. Synacor Zimbra Collaboration Suite1128
3. Zimbra Zimbra74
4. Zimbra Collaboration Server67
5. Zimbra Zimbra Collaboration Suite24
Recent Vulnerabilities
See more →bleepingcomputer-20260820094654
unknown
Critical Zimbra RCE flaw now actively exploited in attacks
Aug 20, 2026⚠ Exploited⚡ Zero-Day🔧 No Patch
CVE-2026-73576
CVSS 6.3medium
Aug 13, 2026🔧 No Patch
CVE-2026-73575
CVSS 3.1low
Aug 13, 2026🔧 No Patch
CVE-2026-73574
CVSS 3.1low
Aug 13, 2026🔧 No Patch
CVE-2026-73573
CVSS 3.1low
Aug 13, 2026🔧 No Patch
CVE-2026-73572
CVSS 6.1medium
Aug 13, 2026🔧 No Patch
CVE-2026-73571
CVSS 3.1low
Aug 13, 2026🔧 No Patch
CVE-2026-73570
CVSS 8.9high
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Aug 13, 2026⚠ Exploited🔧 No Patch
bleepingcomputer-20260710114738
unknown
Zimbra urges customers to patch critical web client XSS flaw
Jul 10, 2026⚠ Exploited⚡ Zero-Day🔧 No Patch
CVE-2026-33373
CVSS 8.8high
Mar 30, 2026🔧 No Patch
Monitor Zimbra in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.