Zimbra is an open-source collaborative messaging software used by many healthcare institutions in France. At the Public Hospital Center of Cotentin (CHPC) in Cherbourg, this platform centralizes emails, calendars, and document sharing for all staff. Its uniqueness in a hospital context lies less in its office functionalities and more in the security and regulatory compliance constraints that govern its use.
CVE-2026-73570 Vulnerability: What Zimbra Requires from Hospital IT Teams
The existing content on Zimbra at CHPC focuses on mastering the interface or managing email folders. None address the most pressing operational reality for a hospital IT department: managing security vulnerabilities.
In the summer of 2026, a critical command injection vulnerability (CVE-2026-73570) was identified in Zimbra Collaboration. It affects the SNMP notification component in versions prior to 10.1.20. The Health CERT, the cybersecurity monitoring portal of the Agency for Digital Health (ANS), issued an alert on August 20, 2026.
As detailed by the Un Soupir website in its analysis of this secure messaging system, proactive management of updates is a constant challenge for institutions that operate Zimbra.
The temporary workaround recommended by the Health CERT is to uninstall the zimbra-snmp package or disable SNMP notifications on instances that do not use this feature. The definitive fix involves updating to at least ZCS 10.1.20.
The scope of the problem extends beyond CHPC. According to a technical monitoring article published in late August 2026, over 270 Zimbra servers had already been compromised worldwide, including 21 in France. For a hospital, a compromised email server means a risk of health data exfiltration, placing this vulnerability in a particularly severe category.

HDS Certification and Hospital Messaging: The Regulatory Framework of Zimbra at CHPC
Zimbra, as software, does not hold a certification. It is the infrastructure on which it is hosted that must meet regulatory requirements. For a hospital like CHPC, the central question is that of HDS certification (Health Data Hosting).
The HDS framework has evolved in recent years with a tightening of obligations. Version 2 of the framework, based on the decree on data sovereignty, strengthens the requirements regarding the location and control of hosted data. Specifically, a hospital using Zimbra must ensure that its host has this certification, that data is transmitted and stored in a compliant environment, and that backups meet the same constraints.
What HDS Compliance Means for Daily Use
For healthcare or administrative staff, these obligations translate into usage constraints that are sometimes perceived as rigid:
- Access to webmail from an unregistered personal device may be restricted or prohibited, depending on the institution’s security policy
- Attachments containing patient data are subject to encryption rules during transit, which can slow down the sending of large files
- Inactive accounts beyond a certain duration are automatically disabled to limit the attack surface
These constraints do not stem from a choice by Zimbra, but from the French regulatory framework applicable to any system handling health data. A hospital using Gmail or Outlook would be subject to the same obligations, provided that the host is HDS certified.
Authentication and Access Control: The Security Layers Around Zimbra
Access to the Zimbra messaging system at CHPC is through the institution’s dedicated URL. The login page offers professional credentials assigned by the IT department. However, the security of a hospital messaging system does not rely solely on a username/password combination.
Several complementary mechanisms come into play in a Zimbra deployment in a hospital setting:
- Multi-factor authentication (MFA), which adds an additional verification step during login (temporary code, authentication app)
- Network filtering, which limits access to webmail to certain IP address ranges or to devices connected to the hospital’s internal network
- Connection logging, which allows the IT department to detect abnormal access (login from an unusual country, multiple failed attempts)
- Centralized rights management via an LDAP directory, which synchronizes accounts with the institution’s information system
This last layer is particularly useful in a hospital. When an employee leaves the institution or changes departments, the deactivation of their Zimbra account is linked to the update of the directory. No orphan accounts mean no forgotten entry points.

Zimbra Interface at CHPC: Modern, Classic, and Practical Usage Choices
Zimbra offers two main versions of its web interface: Modern and Classic. The CHPC login page allows the user to choose, with a third option “Default” that loads the preference saved in the account.
Functional Differences Between the Two Interfaces
The Modern interface is designed to adapt to screens of all sizes, including tablets. It incorporates drag-and-drop features and a more spacious visual layout. The Classic interface retains advanced collaboration and calendar features, favored by users managing complex schedules or shared inboxes between departments.
In a hospital context, the choice between the two interfaces is significant. Administrative staff working at a fixed workstation with a large screen will benefit from the advanced functions of Classic. Healthcare staff who quickly check their messages between consultations, sometimes from a service tablet, will find Modern more suitable.
The setting can be changed in the account preferences (Settings > General > Zimbra Version for Modern, Preferences > General > Sign In for Classic). This setting is individual and does not require intervention from the IT department.
The Zimbra messaging system at CHPC Cherbourg functions as a link in a broader chain of hospital cybersecurity. The CVE-2026-73570 vulnerability serves as a reminder that the reliability of such a tool depends as much on the rigor of updates as on the quality of the interface offered to users.



