logo

Triple Threat Patched: Zimbra 10.1.16 Fixes XSS, XXE & LDAP Injection

ID: 892e564c-b0ed-58bc-b28d-d0ff14eb412a

STIX ID: report--892e564c-b0ed-58bc-b28d-d0ff14eb412a

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-02-13

Date Updated: 2026-04-23

Author: Ddos

...
...

Zimbra 10.1.16 was released to address several security issues — notably Cross-Site Scripting (XSS) in Webmail/Briefcase, an authenticated LDAP injection, and an XML External Entity (XXE) vulnerability in the EWS SOAP endpoint — along with strengthened CSRF protection and restored features implemented with security safeguards; administrators and users are strongly advised to upgrade immediately to mitigate risks like session hijacking, unauthorized directory access, and potential local file disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.