logo

Zimbra Security Update – Patch for XSS, XXE & LDAP Injection Vulnerabilities

ID: 68f99b44-de1f-53e2-b5f7-921c2e7bc646

STIX ID: report--68f99b44-de1f-53e2-b5f7-921c2e7bc646

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Abinaya

...
...

Zimbra released version 10.1.16 (Feb 4, 2026) addressing several high-severity web and directory vulnerabilities — including Webmail/Briefcase XSS, an XXE in the EWS SOAP endpoint, and an authenticated LDAP injection — with fixes for input validation, disabled external entity processing, and query sanitization; the advisory urges admins to test and deploy the patch due to high deployment risk and also lists performance and feature improvements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.