How Zimbra CHPC Cherbourg is Revolutionizing Hospital Communication

The 10.x branch of Zimbra deployed at the Public Hospital Center of Cotentin forces IT teams to make a constant trade-off between service continuity and security hardening. The vulnerabilities published in July and August 2026 specifically target the Classic client, placing the CHPC in front of a structuring technical choice for all its hospital email flows.

Vulnerabilities of the Zimbra Classic client: what the CVEs of 2026 change for the CHPC

The Classic interface now concentrates the majority of documented attack vectors on Zimbra Collaboration Suite. CVE-2026-73570, reported on August 14, 2026, by the Canadian CERT, confirms that environments still exposed to the legacy client require an immediate patch.

The issue goes beyond simple patch management. The Classic UI relies on an outdated JavaScript foundation, whose attack surface expands with each disclosure cycle. The security advisories from July 2026, relayed by Greenbone and ThaiCERT, converge: institutions that maintain Classic in production expose themselves to active exploits, including zero-click types like those attributed to the Laundry Bear group against NATO targets.

For a hospital center handling health data subject to HDS certification, this exposure is not theoretical. We recommend restricting Classic access to fixed workstations on the internal network and forcing the switch to Modern UI on any terminal connected outside the LAN perimeter. The use of Zimbra email CHPC Cherbourg in a multi-site context (Cherbourg, Valognes, Louis Pasteur hospital) makes this segmentation even more urgent.

Doctor checking his Zimbra email on a tablet in the corridor of a modern hospital

Managing Zimbra updates in a hospital setting: patching without interrupting service

Applying a critical patch to hospital email is nothing like a deployment in a typical business environment. Caregivers at CHPC use email continuously, including at night for handover communications between on-call teams. Every maintenance window must be negotiated with health executives, not just with the IT department.

The stable version 10.1.16 from January 2026 laid a foundation, but the patches from July-August add constraints for restarting the mailboxd service. In practice, we observe that institutions of a size comparable to CHPC proceed in two stages:

  • Applying the patch on a pre-production node replicating the MTA and LDAP configuration of Cotentin, with non-regression tests on MSSanté connectors
  • Switching to scheduled maintenance on the production node between 2 AM and 4 AM, with prior notification via SMS channel dedicated to emergency and intensive care services
  • Post-deployment validation by automated sending of control messages to the functional mailboxes of critical services (emergency, SAMU, pharmacy)

This protocol limits downtime to less than two hours. The friction point remains the synchronization of shared calendars: a poorly sequenced restart can cause duplicate appointments on medical schedules.

Zimbra mobile access at CHPC: securing without blocking doctors on the move

Practitioners at CHPC operate across several sites in Cotentin. A doctor based at the Pasteur hospital in Cherbourg can consult in Valognes on the same day. Mobile access to email is not a convenience; it is a condition for coordinating care.

The Modern UI client, responsive by design, partially meets this need. On mobile browsers, it offers full access to email, contacts, and calendar without the need for third-party app installation. This approach reduces the attack surface compared to a poorly configured ActiveSync client.

The difficulty lies in managing personal devices. BYOD remains common in public health institutions where the mobile equipment budget is limited. We recommend conditional filtering:

  • Modern UI access allowed on personal devices only via institutional VPN, with two-factor authentication
  • Blocking the native ActiveSync protocol on smartphones not enrolled in the institution’s MDM
  • Complete deactivation of the Classic client on any access identified as mobile, to eliminate the most exposed attack vector

This configuration preserves ease of use for the doctor while maintaining a level of control compatible with HDS requirements.

Hospital IT team configuring the Zimbra email server in a server room

Integration between Zimbra and MSSanté at the Cotentin Hospital Center

The secure health messaging system (MSSanté) constitutes the regulatory channel for patient data exchanges between professionals. At CHPC, Zimbra serves as the front-end client while MSSanté ensures the encrypted transport of messages containing personal medical information.

This integration requires a specific SMTP configuration. Outgoing messages destined for an MSSanté address pass through a dedicated relay, distinct from the standard MTA used for administrative correspondence. The risk of routing errors exists: an email containing an operative report sent via the classic MTA instead of the MSSanté relay constitutes a clear GDPR non-compliance.

The 10.x branch facilitates this separation through domain transport rules. The administrator can define that any message addressed to a @mssante.fr domain automatically uses the secure connector, without user intervention. This setting removes the human factor in channel selection.

Monitoring flows and traceability

HDS-certified institutions must prove the traceability of each message containing health data. Zimbra 10 exposes structured logs in syslog format, usable by a SIEM. Each MSSanté message can be correlated to a user session identifier, simplifying compliance audits.

CHPC benefits from centralizing these logs with those from the reverse proxy and application firewall. In the event of an incident, the entire chain (authentication, sending, receiving, reading) can be reconstructed, a prerequisite for meeting notification obligations to ARS Normandie.

The Zimbra email system at CHPC Cherbourg is not just a webmail. It is an infrastructure component subject to cybersecurity constraints, health regulations, and operational availability that few open-source solutions manage natively. The gradual migration to Modern UI and the locking down of the Classic client remain the two most effective levers in the short term to reduce the exposure of the Cotentin hospital center.

How Zimbra CHPC Cherbourg is Revolutionizing Hospital Communication