Select your language

Zimbra OSE 10.1.20 with fixed vulnerability

An installation package for the Zimbra OSE 10.1.20 mail system for Ubuntu 20.04 / 22.04 / 24.04 has been prepared, in which the CVE-2026-73570 vulnerability has been eliminated.

You can check for this vulnerability in your mail system right now by running the checksum command for the swatchrc.in file:

$ sha256sum /opt/zimbra/conf/swatchrc.in

If the result matches b0b36f69787aad1ad02b3bccac8043187de7113bea1aa49669e31ed98160c02e, the system is vulnerable! This would allow attackers to transmit arbitrary shell constructs via SMTP requests and gain full root access to the server.

Pay special attention: if your administrative mailbox begins receiving emails with unusual or incomprehensible content, such as those shown in the image or similar, this could indicate an attempt to exploit a vulnerability or an existing server compromise.
Other related signs include the server becoming very slow or the web interface becoming completely inoperable.

What consequences can be expected if it is not eliminated?
Data leak: Attackers gain email administrator rights and access to all correspondence of any account. This means control over all your company's business correspondence, contracts, transactions, etc.
Infrastructure threat: With root access on the Zimbra server, attackers can use it as a springboard to hack other resources on your internal network—servers, personal computers, routers, mobile phones, and more.
Reputational risks: Your server may be involved in sending spam and malicious messages, as well as participating in attacks on third-party Internet resources worldwide.

All this can lead to significant damage, both financial and reputational, to your entire company.

One option is to install a new mail server as quickly as possible that does not have this vulnerability and move all mail from the old server to the new one.

We also recommend using Proxmox Mail Gateway as an additional line of defense against spam, viruses, and undisclosed Zimbra vulnerabilities.

For more information about the Zimbra mail system and to receive a free download link for the Zimbra Open Source Edition 10.1.20 installation package, please visit our page.