Skip to content
TrustList
News

Zimbra 10.1.21 fixes a password-reset flaw, a WebDAV MFA bypass and a batch of stored XSS bugs

Editorial

By TrustList Editorial

Zimbra released Collaboration 10.1.21 on 24 September with a dozen security fixes, including predictable password-recovery codes and WebDAV access before MFA. Canada’s Cyber Centre lists versions before 10.1.21 as affected.

About Zimbra 10.1.21 fixes a password-reset flaw, a WebDAV MFA bypass and a batch of stored XSS bugs

Zimbra 10.1.21 fixes a password-reset flaw, a WebDAV MFA bypass and a batch of stored XSS bugs

24 September 2026 — Zimbra released Zimbra Collaboration Suite 10.1.21 ("Daffodil") on 24 September 2026. Alongside new features, the release fixes a dozen security issues, and Zimbra tells administrators that unpatched environments "carry unmitigated security risks" and should apply it immediately. On 25 September the Canadian Centre for Cyber Security published advisory AV26-964, listing Zimbra Collaboration Suite 10.1 before 10.1.21 as affected and urging users to apply the update.

The fixes that matter most

Zimbra's security advisory table lists these fixes against release 10.1.21:

  • Password recovery: a flaw in self-service password recovery "that could allow an unauthenticated attacker to predict recovery codes and reset a user's password".
  • WebDAV and MFA: WebDAV accepted tokens issued before multi-factor authentication was complete. Pre-MFA tokens are now rejected, so users must finish MFA before reaching WebDAV resources.
  • OnlyOffice integration: one flaw that could allow unauthorised file writes and remote code execution "under specific conditions", and a server-side JavaScript injection that could let an authenticated user run commands on the server.
  • Stored cross-site scripting: several cases in the Classic Web Client, triggered through crafted sender names (CVE-2026-66912), attachment headers (CVE-2026-66911), share invitations, email content and calendar counter-proposals, plus one in the Modern Web Client through share invitations.
  • Components: OpenJDK upgraded to 17.0.19 and the NGINX module updated.

Most entries have no CVE number or severity score yet; the table shows them as "TBD". Neither Zimbra nor the Cyber Centre says any of the flaws has been exploited. The advisory table names 10.1.21 as the only fix release for these entries and notes that older, unsupported versions often carry the same vulnerabilities.

Who is affected

Organisations that run Zimbra themselves: hosting companies and internet providers offering webmail, universities, public bodies and managed service providers with multi-tenant Zimbra platforms. Zimbra says its software runs more than 6,000 deployments in over 140 countries.

What to do

  • Upgrade to 10.1.21. If you are on an older or unsupported line, plan the move to a supported 10.1 release rather than waiting for a back-port.
  • Until upgraded, review whether self-service password recovery needs to stay enabled, and look in logs for password resets users did not ask for.
  • Check WebDAV access logs for sessions from accounts with MFA enabled that did not complete a second factor.
  • If you use the OnlyOffice integration, treat the upgrade as urgent.
  • If a provider hosts Zimbra for you, ask in writing when it will be on 10.1.21.

Sources