
When a CHPC agent opens their Zimbra inbox on a Monday morning and finds an alert message from the IT department requesting to change all application passwords, the question is no longer whether the messaging system is practical. It is whether it can withstand an ongoing attack. This is exactly the scenario that several French hospitals have experienced in recent months, and the Public Hospital Center of Cotentin is not exempt from this reality.
CVE-2026-73570 Vulnerability on Zimbra: What the CHPC Needs to Check as a Priority
In August 2026, CISA added the CVE-2026-73570 vulnerability to its catalog of actively exploited flaws. This vulnerability allowed for remote code execution on Zimbra servers prior to version 10.1.20. For a hospital that handles medical reports, on-call schedules, and sensitive administrative data, this type of breach is a game changer.
The information that many official communications have not highlighted: exploitation depends on a non-default configuration. The zimbra-snmp component must be installed and SNMP notifications enabled for the server to be truly exposed. A CHPC administrator utilizing the resource available as a secure messaging on Un Soupir will find this type of technical detail to assess their actual level of exposure.
In practical terms, even before applying the patch, the attack surface can be reduced by disabling SNMP notifications if they are not used for daily monitoring. The update remains necessary, but checking the actual exposure of the server takes precedence over the simple reflex of patching.

Zimbra Session Theft: When the Password is No Longer Enough
Another wave of attacks documented at the end of July 2026 targets a different vector. The CVE-2025-66376 vulnerability, exploited on Zimbra instances, does not attempt to guess a password. It directly steals the session token of the logged-in user.
The published analyses describe a specific scenario: the attacker retrieves authentication tokens, two-factor authentication backup codes, and can even create a Zimbra application password that completely bypasses the 2FA mechanism. In a hospital context, this means that a compromised account provides access to medical exchanges without the user noticing anything.
Concrete Measures for Users at the CHPC
- Never leave a Zimbra session open on a shared workstation (treatment room, reception desk). Explicitly logging out invalidates the session token.
- Monitor for the appearance of unknown application passwords in account settings. Their unsolicited presence is a marker of compromise.
- Report any abnormal behavior to the IT department: messages read without user action, automatically created folders, unknown forwarding rules.
Session theft renders two-factor authentication insufficient if the workstation itself is compromised. This is not a theoretical risk: security bulletins document active exploitations on production Zimbra servers.
Zimbra 10 at the CHPC: What the Recent Branch Changes Daily Operations
The CHPC uses Zimbra to centralize emails, shared calendars, and contact management. The 10.x branch brings improvements in handling large attachments, a sensitive point when dealing with heavy medical documents (imaging, specialist reports).
The Modern interface, responsive and suitable for all screens, coexists with the Classic interface oriented towards desktop use. Feedback varies on this point: some agents prefer the Classic version for its information density on the screen, while others appreciate Modern on tablets during bedside visits.
Shared Calendar and Coordination Between Departments
The most used feature beyond simple email remains the shared calendar. For a care service, viewing a colleague’s availability in real time avoids unnecessary phone calls. An event is created, a room or equipment is associated, and the confirmation arrives in the recipient’s inbox.
Sharing email folders among colleagues in the same department also helps manage continuity during absences. A health manager can delegate access to their functional inbox without sharing their personal credentials, maintaining the traceability of actions.

Health Data Security and Compliance: The Real Constraints of a Hospital Zimbra
A public hospital does not host its messaging like a small business. The data that passes through Zimbra at the CHPC includes information covered by medical confidentiality. Hosting must meet the requirements of HDS certification (Health Data Hosting), and the integration with the MSSanté system conditions secure exchanges between healthcare professionals.
GDPR compliance imposes an additional framework: email retention periods, patients’ right to access exchanges concerning them, logging of access to functional inboxes. The Zimbra administrator at the CHPC does not only manage a mail server; they manage a link in the hospital’s digital trust chain.
Best Hardening Practices Specific to the Zimbra Context
- Restrict access to the Zimbra administration panel to only the IP addresses of the hospital’s internal network.
- Disable unused components (third-party zimlets, IMAP/POP protocols if webmail suffices) to reduce the attack surface.
- Implement regular rotation of TLS certificates and ensure that SMTP exchanges between Zimbra and MSSanté servers are end-to-end encrypted.
- Audit server-side filtering rules: an attacker who compromises an account can create silent redirection rules.
The security of a hospital Zimbra is not limited to software updates. Each activated component is a potential door, and in an environment where system availability is as critical as its confidentiality, hardening involves documented and regularly revised configuration choices.
The CHPC, like other hospital centers in Cotentin, faces increasing pressure on the cybersecurity of its collaborative tools. Zimbra remains a robust and proven solution for hospital messaging, provided that each critical update is applied promptly and default configurations are systematically questioned.