CISA added Zimbra’s CVE-2026-73570 (unauthenticated command injection, CVSS 8.9) to the KEV catalog on August 21, 2026 — federal deadline August 24. The only fix is 10.1.20. Zimbra 8.8.15, 9.0 and 10.0 are past vendor support and get nothing — and the vendor’s own patch history shows the backports stopping one line at a time, unannounced.
One fix, one version — and three lines that get nothing
| Line | GA | Vendor status (Zimbra release index) | Last patch shipped | CVE-2026-73570 fix |
|---|---|---|---|---|
| Zimbra 10.1 (Daffodil) | 2024-07-16 | Current — no end date published | 10.1.20, 2026-07-20 | Yes — 10.1.20 |
| Zimbra 10.0 (Daffodil) | 2023-03-08 | End of General Support 2025-06-30 | 10.0.18, 2025-11-06 | None |
| Zimbra 9.0 (Kepler) | 2020-04-07 | End of Technical Guidance 2025-06-30 | 9.0.0 P46, 2025-06-18 | None |
| Zimbra 8.8.15 (Joule, LTS) | 2019-07-22 | End of Technical Guidance 2024-12-31 | — | None |
What's covered
- Key Dates at a Glance
- What the vulnerability actually is
- One fix, one version — and three lines that get nothing
- The backport window closed one line at a time, and nobody announced it
- Zimbra is a KEV regular
- What to do this week
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-zimbra-eol
Top comments (0)