Zimbra security advisory (AV26-964)
Canada's Cyber Centre urges updates for Zimbra Collaboration Suite releases before 10.1.21 over unspecified vulnerabilities.
The Canadian Centre for Cyber Security published advisory AV26-964 on September 25, 2026, stating that Zimbra Collaboration Suite (Daffodil) versions before 10.1.21 are affected by vulnerabilities. The bulletin does not name CVEs, describe the flaws, or report exploitation. It directs users and administrators to Zimbra's release notes and to apply updates as they become available.
- Advisory AV26-964 covers Zimbra Collaboration Suite (Daffodil) before 10.1.21.
- The bulletin gives no CVE identifiers, severity ratings, or exploitation details.
- Administrators are told to review Zimbra's links and apply available updates.
Full article63 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-964
Date: September 25, 2026
As of September 25, 2026, Zimbra is affected by vulnerabilities in the following product:
- Zimbra Collaboration Suite (ZCS) (Daffodil)
- Prior to 10.1.21
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/zimbra-security-advisory-av26-964