logo

Zimbra Issues Security Update to Address XSS, XXE, and LDAP Injection Flaws

ID: 45712a39-3d98-5713-b984-6b9a5e7e2ce3

STIX ID: report--45712a39-3d98-5713-b984-6b9a5e7e2ce3

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2026-02-13

Date Updated: 2026-04-22

Author: Divya

...
...

Zimbra released patch 10.1.16 addressing several high-severity vulnerabilities—including Cross-Site Scripting (XSS) in Webmail/Briefcase, authenticated LDAP injection, and an XXE in the EWS SOAP endpoint—plus a CSRF fix; administrators are urged to apply the update after backups due to a noted high deployment risk. The release also adds backup/restore improvements, zstd compression and deduplication, beta Ubuntu 24 support, and fixes PDF preview stability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.