logo

Zimbra Issues Emergency Patch for Critical SSRF Vulnerability in Chat Proxy Configuration

ID: aba16249-3e7e-5e2a-b2c5-eb5d3ba6663e

STIX ID: report--aba16249-3e7e-5e2a-b2c5-eb5d3ba6663e

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2025-10-17

Date Updated: 2026-04-22

Author: Ddos

...
...

Zimbra released an emergency patch (10.1.12) on October 16, 2025 to fix a critical Server-Side Request Forgery (SSRF) in its chat proxy configuration that could allow attackers to access internal resources, retrieve sensitive metadata, or pivot to further attacks; administrators on versions 10.1.5–10.1.11 are urged to update immediately, reactivate licenses with zmlicense -a <license_key>, and note multi-server version-tag nuances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.