Security Alert: Zimbra Security Update – July 2026
Zimbra has released a security update addressing multiple critical vulnerabilities in SNMP monitoring, the Classic Web Client, and mail forwarding, EWS extension along with other components. These vulnerabilities could expose systems to compromise and unauthorized access.
Affected Systems:
The following components are affected, but not limited to:
Zimbra Collaboration Suite (ZCS): SNMP monitoring, Classic Web Client, mail forwarding, and EWS extension in versions prior to 10.1.20.
Security Risks
Identified vulnerabilities can be exploited by attackers to execute system commands, inject malicious scripts, bypass security controls, steal email data, or gain unauthorized access to affected systems.
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
1. Update affected Zimbra Collaboration Suite (ZCS) installations as soon as possible to the latest supported security releases to address the vulnerabilities.
Upgrade to the supported versions:
Zimbra Collaboration Suite (ZCS): Upgrade to version 10.1.20 or above, to remediate vulnerabilities affecting SNMP monitoring, Classic Web Client, mail forwarding, EWS extension, and related components.
2. Before applying updates, ensure that a current and verified backup is available and can be restored if needed.