Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Zimbra Security Update – July 2026

Zimbra has released a security update addressing multiple critical vulnerabilities in SNMP monitoring, the Classic Web Client, and mail forwarding, EWS extension along with other components. These vulnerabilities could expose systems to compromise and unauthorized access.
 
Affected Systems:
 
The following components are affected, but not limited to:
 
  • Zimbra Collaboration Suite (ZCS): SNMP monitoring, Classic Web Client, mail forwarding, and EWS extension in versions prior to 10.1.20.
 
Security Risks
 
Identified vulnerabilities can be exploited by attackers to execute system commands, inject malicious scripts, bypass security controls, steal email data, or gain unauthorized access to affected systems.
 
For additional information on Zimbra security updates and available patches, please refer to the official Zimbra Product News.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Update affected Zimbra Collaboration Suite (ZCS) installations as soon as possible to the latest supported security releases to address the vulnerabilities.
 
Upgrade to the supported versions:
 
 
2. Before applying updates, ensure that a current and verified backup is available and can be restored if needed.
 
3. For additional details on patch installation and mitigation, refer to Zimbra’s official guidance.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

22 July 2026

© 2026 National Cyber Security Authority