OFFSEC · Offensive Security

Zimbra’s critical flaw this month is in a document editor. August’s was in an SNMP agent. Neither is the mail server

CVE-2026-93643 is an unauthenticated remote code execution flaw in Zimbra's OnlyOffice integration, fixed on 24 September. The flaw exploited in August lived in an optional SNMP package. Exposure in both cases is set by which components are enabled, and a version inventory cannot see that.

Zimbra published release 10.1.21 on 24 September 2026 with twelve security fixes. [2] Two of them are in the OnlyOffice document editing integration. One is described by the vendor as a security issue that could allow unauthorised file writes and remote code execution under specific conditions, reported by Jonah Burgess of Rapid7. The other is a server-side JavaScript injection issue permitting an authenticated user to execute commands on the server, reported by the security operations centre of the Vatican City State Governorate. [1]

The first of those carries CVE-2026-93643, published on 25 September at CVSS 9.8, with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and two weakness classes, CWE-22 for path traversal and CWE-863 for incorrect authorisation. Affected builds are Zimbra Collaboration Suite below 10.1.21. The record states that where OnlyOffice document editing is enabled, an unauthenticated attacker with access to a public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as the zimbra user. [3] The Canadian Centre for Cyber Security issued advisory AV26-964 on 25 September covering builds prior to 10.1.21. [4]

The condition is the finding

Read the record again for what it requires. Not a version alone. OnlyOffice document editing has to be enabled, and a public Briefcase document has to be reachable. An instance running an affected build with that integration switched off is not exploitable by this path. An instance running the same build with it switched on is exploitable without credentials.

That is the same shape as the flaw that was actually exploited last month. CVE-2026-73570 is a command injection issue in Zimbra’s SNMP monitoring component, and it is only exploitable where the optional zimbra-snmp package is installed and SNMP notifications are enabled, which is not the default. [6][8][10] Zimbra disclosed the issue on 26 June 2026 and shipped what it described as a permanent fix in 10.1.20 on 20 July. [5][8] Neither flaw is in the mail transfer or mailbox code. One is in a bundled third-party document editor, the other in a monitoring agent that many administrators would not describe as part of the product at all.

This cuts in two directions and most estates only account for one of them. The configuration gate genuinely reduces the exploitable population: of the unpatched instances counted in August, not all were vulnerable. [7][8][9] It also means the exposed population cannot be enumerated from a version list. The question that determines risk is which optional packages are installed and which integrations are enabled, and that is recorded in the product’s own configuration rather than in the asset register most organisations maintain. A team that answers "are we affected" by comparing build numbers will produce a confident answer to a different question.

What happened when the gate was open

The August case is the empirical part. CERT Polska flagged in-the-wild exploitation of CVE-2026-73570 in mid-August, publishing indicators of compromise without further campaign detail. [7][9][10] The Shadowserver Foundation then scanned for exploitation artefacts and recorded 155 compromised internet-facing instances on 20 August, rising to 274 on 22 August. [8] Shadowserver stated that compromises associated with the flaw were spreading and put the figure at 274 instances on that date. [7] At least 8,200 instances remained on older builds. [7][8][9]

The patch had been available for a month when the first compromises were counted. Nothing in that sequence involved a flaw without a fix. Hong Kong’s HKCERT issued a high-risk bulletin on 24 August covering four Zimbra flaws in builds prior to 10.1.20 and recorded CVE-2026-73570 as actively exploited. [6] Publishers disagree on the catalogue timeline: one account gives 21 August as the date the flaw entered the US known-exploited catalogue with a three-day federal deadline of 24 August, another describes the addition as late August, and SecurityWeek’s report, written as the campaign surfaced, records the flaw as not yet added. [7][9][10] The disagreement is about the administrative record, not about whether the attacks happened.

Who is looking

Zimbra does not need a reason to be examined. On 24 July 2026, 27 agencies including the NSA, FBI, CISA, Australia’s ACSC, Canada’s Cyber Centre, NCSC-NZ and NCSC-UK published a joint advisory on a group it designates LAUNDRY BEAR, described in the advisory as a Russian state-supported advanced persistent threat, which it states has been targeting and compromising users of Zimbra Collaboration Suite since at least July 2025 across defence industrial base, government, education, energy, law enforcement, media, non-governmental and technology organisations. [13] That is the advisory’s own attribution language, and R3KONX reports it as such.

The rest of the 10.1.21 set matters for the same reason. It includes stored cross-site scripting issues in both the Classic and Modern web clients: CVE-2026-66912 in sender display names on reply and forward, reported by CERT.PL, and CVE-2026-66911 in attachment Content-Location headers, reported by Suraj Disoja and CERT.PL. [1] Two further issues are recorded as CVE-2026-93642, a stored cross-site scripting flaw reached through a forged share invitation in Zimbra Modern, and CVE-2026-93647, the same class of flaw reached through markup in the From field of a calendar counter-proposal message in Classic. [12] Rapid7 is reported as warning that weaknesses of this kind can support business email compromise operations that manipulate the records employees rely on, and that complicate later investigation. [12] The release also raises OpenJDK to 17.0.19 and ends support for Ubuntu 18.04. [2]

The reporter list is worth noting on its own. A commercial research team, a national CERT, an independent researcher and a government security operations centre all reported into the same release. Coordinated disclosure is functioning. Application is where these cases fail.

What to do

  • Enumerate installed optional packages and enabled integrations on every Zimbra host, and treat that list as the exposure inventory. Whether zimbra-snmp is present, whether SNMP notifications are on, and whether OnlyOffice document editing is enabled are the facts that decide both of these cases. [3][8]
  • Identify public Briefcase documents. Reachability of one is a stated precondition of CVE-2026-93643, so the share inventory is part of the patching decision rather than a separate housekeeping task. [3][11]
  • Upgrade to 10.1.21, which closes the OnlyOffice issues together with the web client flaws, and confirm the build afterwards rather than assuming the upgrade path completed. [1][2]
  • For estates that were on builds earlier than 10.1.20 during August, treat patching and investigation as separate work. Compromises were counted a month after the fix shipped, so apply CERT Polska’s published indicators and hunt for artefacts rather than closing the item on version alone. [7][10]
  • Review web client exposure for the cross-site scripting issues, given that the stated impact is mailbox access in an authenticated session and, on the research team’s account, manipulation of records used for business decisions. [1][12]
  • Plan the Ubuntu 18.04 migration now, since support for it ends after this release and the next security fix will not reach those hosts. [2]

The offensive security read

Two consecutive Zimbra security releases have put the most serious flaw outside the mail server: once in a bundled document editor, once in a monitoring agent that is optional to install. In both cases the severity score describes the code and says nothing about whether a given host meets the conditions to be attacked. That gap is where the practical work sits. An organisation that can produce a list of which integrations are enabled across its collaboration estate has a real answer. One that can produce only build numbers has a plausible answer, which in August was worth 274 compromised servers a month after the fix was published. For government and university estates across Southeast Asia, where this platform is widely deployed and a regional CERT has already issued a high-risk bulletin on the earlier flaw, the configuration inventory is the item to build. The next flaw in a bundled component will ask the same question.

Sources

Every R3KONX article cites its primary material. 13 sources, in order of first citation. Links open the original publication.

  1. Zimbra Security Advisories Zimbra (Tech Center wiki) · 2026-09-24
  2. Zimbra Releases/10.1.21 Zimbra (Tech Center wiki) · 2026-09-24
  3. CVE-2026-93643: Zimbra Collaboration Suite (ZCS) Path Traversal Strix · 2026-09-25
  4. Zimbra security advisory (AV26-964) Canadian Centre for Cyber Security · 2026-09-25
  5. Patch Release Update: Zimbra 10.1.20 Zimbra Blog · 2026-07-20
  6. Zimbra Multiple Vulnerabilities HKCERT · 2026-08-24
  7. Hackers breached over 270 Zimbra servers in ongoing attacks BleepingComputer · 2026-08-24
  8. Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Help Net Security · 2026-08-25
  9. 274 Zimbra Servers Compromised, 8,200 Unpatched eSecurity Planet · 2026-08-26
  10. Hackers Target Zimbra Servers in Active Exploitation Campaign SecurityWeek · 2026-08-21
  11. CVE-2026-93643: Zimbra OnlyOffice Unauthenticated Path Traversal RCE as Zimbra User TheHackerWire · 2026-09-25
  12. Critical Zimbra RCE and XSS Flaws Enable Mailbox Takeover and Enterprise Record Manipulation Mallory · 2026-09-26
  13. Russian state-supported cyber actors conduct phishing campaign targeting users of Zimbra Collaboration Suite NCSC New Zealand · 2026-07-24

Researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveats: Zimbra's own advisory describes the two OnlyOffice fixes in 10.1.21 without attaching CVE identifiers to them, so the mapping of the unauthenticated file-write issue to CVE-2026-93643 rests on the CVE record's description matching the vendor's text, and the reporter credits are taken from the vendor advisory as written. cisa.gov was not reachable from this desk, so the Known Exploited Vulnerabilities addition date and federal deadline for CVE-2026-73570 are carried from three secondary publishers, one of which was written before the entry was added and records it as absent. NVD analysis of CVE-2026-93643 was pending, so its CVSS vector and affected-version range are carried from a vulnerability aggregator. The MyCERT advisory portal returned an error, so no current Malaysian national advisory could be read. No exploitation of CVE-2026-93643 had been reported at the time of writing, and no exploitation detail is reproduced. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.