DEV Community

endoflife-ai
endoflife-ai

Posted on Originally published at endoflife.ai

Zimbra End of Life: 8.8.15, 9.0 and 10.0 Get No Fix for Exploited CVE-2026-73570

CISA added Zimbra’s CVE-2026-73570 (unauthenticated command injection, CVSS 8.9) to the KEV catalog on August 21, 2026 — federal deadline August 24. The only fix is 10.1.20. Zimbra 8.8.15, 9.0 and 10.0 are past vendor support and get nothing — and the vendor’s own patch history shows the backports stopping one line at a time, unannounced.

One fix, one version — and three lines that get nothing

Line GA Vendor status (Zimbra release index) Last patch shipped CVE-2026-73570 fix
Zimbra 10.1 (Daffodil) 2024-07-16 Current — no end date published 10.1.20, 2026-07-20 Yes — 10.1.20
Zimbra 10.0 (Daffodil) 2023-03-08 End of General Support 2025-06-30 10.0.18, 2025-11-06 None
Zimbra 9.0 (Kepler) 2020-04-07 End of Technical Guidance 2025-06-30 9.0.0 P46, 2025-06-18 None
Zimbra 8.8.15 (Joule, LTS) 2019-07-22 End of Technical Guidance 2024-12-31 None

What's covered

  • Key Dates at a Glance
  • What the vulnerability actually is
  • One fix, one version — and three lines that get nothing
  • The backport window closed one line at a time, and nobody announced it
  • Zimbra is a KEV regular
  • What to do this week

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-zimbra-eol

Top comments (0)