On September 25, 2026, Canada’s Cyber Centre published advisory AV26-964 for Zimbra Collaboration Suite Daffodil. It identifies versions before 10.1.21 as affected and points administrators to Zimbra’s update information.
Zimbra’s security page describes several fixes associated with this release line. The advisory does not prove that a particular server was compromised; it does provide a concrete reason to check versions and exposed components quickly.
What 10.1.21 covers
Zimbra’s security page links version 10.1.20 to the fix for command injection in the SNMP monitoring component when notifications are enabled. Version 10.1.21 addresses additional vulnerabilities, including issues in the webmail and OnlyOffice integration. The vendor’s security page remains the source of truth for the exact fixes and their applicability.
Do not infer that every component is active from a version number alone. Record the modules actually used, integrations and administration paths before upgrading.
The inventory to build
List ZCS Daffodil servers, versions, storage nodes and any relay or test environments. Check older installations that are no longer on supported releases as well: a mail service that still responds should not be treated as patched simply because it is operational.
Review exposure of webmail, administration services and SNMP. Network restrictions reduce reachable surface during maintenance, but they do not replace the official update.
Patch while preserving evidence
Follow Zimbra’s procedure, take a verified backup and confirm the version on every node after restart. Preserve SMTP, webmail, LDAP and system logs before rotating credentials or cleaning hosts.
Look for unusual administrative sign-ins, configuration changes, new accounts and unexpected SNMP activity. If there is credible evidence of compromise, preserve it before deleting an account or rebuilding a server.
Accounts, delegations and secrets
Review mailbox delegations, administrator accounts and credentials used by relays, backups and monitoring tools. If a server may have been manipulated, rotate passwords, API keys and service secrets after defining the recovery order.
Warn users that a reset message received during maintenance may be fraudulent. Fixing the server does not by itself prove the integrity of every mailbox.
How Soclyde fits
Soclyde does not patch Zimbra or verify a mail server’s integrity. It can help keep administration, relay and backup access in an encrypted local-first vault, with separate secrets for each use.
That organisation makes post-investigation rotation easier without turning the vault into a substitute for patching, logs or incident response.
The takeaway
Zimbra’s update guidance and the Canadian advisory cover Daffodil versions before 10.1.21. Inventory components, patch, preserve logs and review access. Read the secure password generator guide or contact Soclyde.



