Skip to content
Zimbra Releases Critical Security Update for XSS, XXE, and LDAP Injection Vulnerabilities

Zimbra Releases Critical Security Update for XSS, XXE, and LDAP Injection Vulnerabilities

First seen 13 Feb 2026, 13:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

Zimbra has released version 10.1.16 on February 4, 2026, to address high-severity vulnerabilities including cross-site scripting (XSS), XML external entity (XXE), and LDAP injection. Administrators are urged to upgrade immediately to protect their email server deployments from potential exploits.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2026-02-04
Zimbra version 10.1.16 released to address vulnerabilities
2026-02-13
Articles published announcing the security update

More articles in this cluster (2)