SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityZimbraEmail

Zimbra: apply the 10.1.21 security update

Zimbra Collaboration Suite 10.1.21 addresses a new set of vulnerabilities. Here is the inventory, patching and access review to run.

By Soclyde Team

An administrator checks an update in a mail operations room

In summary

  • Canada’s Cyber Centre identifies Zimbra Collaboration Suite Daffodil before 10.1.21 as affected by vulnerabilities published on September 25.
  • Zimbra’s security page links 10.1.20 to the fix for command injection in the SNMP monitoring component when notifications are enabled; 10.1.21 addresses additional vulnerabilities.
  • Inventory the servers, apply the official update and review mailbox accounts, delegations and mail-system logs.

Explore next

Soclyde resources

Article contents

On September 25, 2026, Canada’s Cyber Centre published advisory AV26-964 for Zimbra Collaboration Suite Daffodil. It identifies versions before 10.1.21 as affected and points administrators to Zimbra’s update information.

Zimbra’s security page describes several fixes associated with this release line. The advisory does not prove that a particular server was compromised; it does provide a concrete reason to check versions and exposed components quickly.

What 10.1.21 covers

Zimbra’s security page links version 10.1.20 to the fix for command injection in the SNMP monitoring component when notifications are enabled. Version 10.1.21 addresses additional vulnerabilities, including issues in the webmail and OnlyOffice integration. The vendor’s security page remains the source of truth for the exact fixes and their applicability.

Do not infer that every component is active from a version number alone. Record the modules actually used, integrations and administration paths before upgrading.

The inventory to build

List ZCS Daffodil servers, versions, storage nodes and any relay or test environments. Check older installations that are no longer on supported releases as well: a mail service that still responds should not be treated as patched simply because it is operational.

Review exposure of webmail, administration services and SNMP. Network restrictions reduce reachable surface during maintenance, but they do not replace the official update.

Patch while preserving evidence

Follow Zimbra’s procedure, take a verified backup and confirm the version on every node after restart. Preserve SMTP, webmail, LDAP and system logs before rotating credentials or cleaning hosts.

Look for unusual administrative sign-ins, configuration changes, new accounts and unexpected SNMP activity. If there is credible evidence of compromise, preserve it before deleting an account or rebuilding a server.

Accounts, delegations and secrets

Review mailbox delegations, administrator accounts and credentials used by relays, backups and monitoring tools. If a server may have been manipulated, rotate passwords, API keys and service secrets after defining the recovery order.

Warn users that a reset message received during maintenance may be fraudulent. Fixing the server does not by itself prove the integrity of every mailbox.

How Soclyde fits

Soclyde does not patch Zimbra or verify a mail server’s integrity. It can help keep administration, relay and backup access in an encrypted local-first vault, with separate secrets for each use.

That organisation makes post-investigation rotation easier without turning the vault into a substitute for patching, logs or incident response.

The takeaway

Zimbra’s update guidance and the Canadian advisory cover Daffodil versions before 10.1.21. Inventory components, patch, preserve logs and review access. Read the secure password generator guide or contact Soclyde.

Frequently asked questions

Which Zimbra version should administrators check?

The Canadian advisory covers Zimbra Collaboration Suite Daffodil before 10.1.21. Verify the version actually running and consult Zimbra’s security notes before selecting an upgrade path.

Does this affect every Zimbra deployment?

No. Exposure depends on the version, enabled components and configuration. An old or unsupported installation should nevertheless be treated as a priority until it is verified.

What should teams review after patching?

Preserve logs, review administrative sign-ins, mailbox delegations, SNMP jobs and configuration changes. Rotate secrets reachable from the server if unusual activity is confirmed.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading