Skip to content

Avecdessi

Blog

Discover the new features of Zimbra messaging in Cherbourg for 2026

The Zimbra messaging system used by the public agents and services of Cherbourg will undergo changes in 2026 that go beyond just a simple interface change. A…

Professionnelle utilisant la messagerie Zimbra sur un ordinateur dans un bureau moderne à Cherbourg

The Zimbra messaging system used by public agents and services in Cherbourg is undergoing changes in 2026 that go beyond a simple interface update. A critical security vulnerability, mandatory updates, and new collaborative features are reshaping the daily lives of users. Here’s what is changing concretely, and what it means for the structures in Cotentin.

CVE-2026-73570 Vulnerability: The Zimbra Update that Conditions Everything Else

Do you use Zimbra daily without ever checking the version number? In 2026, this habit could pose a real problem. In August 2026, several national CERTs confirmed the active exploitation of a vulnerability referenced as CVE-2026-73570. It affects the SNMP component of the Zimbra Collaboration Suite.

In practical terms, this vulnerability allows an attacker to execute commands directly at the system level without needing to authenticate. The condition: the optional zimbra-snmp package must be installed and SNMP notifications must be enabled. This type of configuration exists in many Norman local authorities, including Cherbourg.

To fully understand the new features of Zimbra messaging in Cherbourg, one must start from this observation: any Zimbra instance prior to version 10.1.20 is considered vulnerable if SNMP is active. Zimbra has released a permanent fix in this version, which was released on July 20, 2026. Structures that have not yet applied this patch must, at a minimum, disable SNMP notifications as a temporary measure.

More than 270 Zimbra servers have been compromised as part of this attack campaign. The U.S. agency CISA has added this vulnerability to its catalog of exploited vulnerabilities, effectively imposing a correction deadline on the affected administrations.

Man consulting the new features of Zimbra 2026 in a co-working space

Zimbra in Cherbourg: What Version 10.1.20 Brings to Users

Beyond the security fix, version 10.1.20 includes functional improvements that change the daily experience. Zimbra offers two interfaces: Modern and Classic. The Modern version, designed to be responsive, adapts to tablets and smartphones. The Classic version remains favored by users accustomed to advanced calendar and collaborative management functions on computers.

Storage Capacity and Integrated Tools

The national deployment of Zimbra for public agents comes with a storage capacity increased to 20 GB per mailbox. This threshold allows for several years of exchanges without external archiving. The tool also integrates a calendar, a shared calendar, and a directory, reducing dependence on third-party software.

Enhanced Anti-Spam and Anti-Phishing Filtering

Zimbra 2026 includes advanced spam and malware filtering, as well as protection against phishing attacks. Filtering rules are customizable: each user can create their own criteria to sort incoming messages. This point is particularly useful in Cotentin, where local authorities receive an increasing volume of fraudulent emails targeting administrative services.

Messaging Security in Normandy: Obligations and Local Best Practices

The city of Cherbourg, like other Norman local authorities, must comply with ANSSI recommendations regarding messaging. The CVE-2026-73570 vulnerability illustrates a point that many structures underestimate: an unpatched messaging server becomes an entry point for ransomware attacks.

Recent news confirms this. In Tarnos, a Zimbra server was shut down after a ransom demand, and an investigation was opened to determine if data had been exfiltrated. This type of incident is not reserved for large metropolitan areas. Municipalities in Cotentin, with sometimes limited IT teams, are prime targets.

Here are the concrete measures that Zimbra administrators in Cherbourg and Cotentin should verify:

  • Confirm that the Zimbra instance is running on version 10.1.20 or later, the only version that fixes the SNMP vulnerability
  • Disable the zimbra-snmp package if SNMP notifications are not used, even after the update
  • Enable two-factor authentication for all accounts with administrative rights
  • Ensure that offline mode does not store sensitive data on unencrypted devices

Administrative office in Cherbourg with the new Zimbra messaging interface displayed on screen

Configuring Zimbra with a Local Email Client in Cotentin

Many agents prefer to use Thunderbird or Outlook rather than webmail. Configuration remains possible in 2026, but the settings change depending on the academy or local authority. For structures attached to the Caen academy (which covers part of Manche), the IMAP and SMTP servers are specific.

The classic trap: using the settings of an old Roundcube webmail to connect to Zimbra. The two systems still coexist for some functional mailboxes (schools, municipal services), but the credentials and servers are not interchangeable. An error message upon connection often means that the protocol or port is incorrect, not that the password is wrong.

Here are the points to check before setting up a local client:

  • Use the IMAP protocol (not POP3) to maintain synchronization with the Zimbra webmail
  • Enter the secure IMAP port (SSL/TLS) provided by the local authority administrator
  • Do not reuse old Roundcube profiles: create a new account in Thunderbird or Outlook

The official login page, accessible at messagerie.cherbourg.fr, allows you to choose between the Modern and Classic interfaces. If the connection fails with the SSO parameter, testing direct access via the URL without SSO may resolve the issue.

The year 2026 marks a technical turning point for Zimbra in Cherbourg rather than an aesthetic one. The priority is not to discover a new interface, but to ensure that the server hosting the emails of the city and Cotentin withstands ongoing attack campaigns. Version 10.1.20 is not an option; it is the minimum compliance threshold.

Discover the new features of Zimbra messaging in Cherbourg for 2026