Zimbra Denial of Service Vulnerability
CSIRTS triage
- What
- A denial of service vulnerability has been discovered in Zimbra.
- Who is affected
- Deployments of Zimbra are affected.
- Urgency
- Remediation is urgent due to the potential for service disruption.
- Action
- Apply the latest security updates for Zimbra.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Zimbra
Get an email when a new Zimbra advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/zimbra-denial-of-service-vulnerability_20260622
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Elevated exploitation riskCVE-2026-4997528.0% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 98% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-49975 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] HTTP/2 implementations: Vulnerability allows denial of servicecert-bund
- unknownMultiple vulnerabilities in Fortinet products (August 13, 2026)cert-fr-avis
- unknownHTTP/2 Bomb CVE-2026-49975fortinet
- highCVE-2026-49975: Apache HTTP Server: mod_http2 denial of servicemsrc
More from HKCERT Security Bulletins
- unknownGoogle Chrome Multiple Vulnerabilities2026-08-26
- unknownVeeam Backup & Replication Information Disclosure Vulnerability2026-08-26
- unknownZimbra Multiple Vulnerabilities2026-08-24
- unknownMicrosoft Edge Multiple Vulnerabilities2026-08-24
- unknownGoogle Chrome Multiple Vulnerabilities2026-08-21