Zimbra Releases/10.1.19

Revision as of 04:46, 7 July 2026 by Pajari (talk | contribs) (→‎Security Fixes)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Zimbra Daffodil (v10.1.19) Patch Release

Release Date: July 7, 2026

Note for Customers Upgrading:

  • Customers upgrading from ZCS 10.1.x: No additional action is required. If the SNMP mitigation has already been applied on your existing 10.1.x deployment, it will remain effective after upgrading to ZCS v10.1.19.
  • Customers upgrading from ZCS 10.0.x, 9.0.x, or 8.8.15: The SNMP mitigation must be updated and reapplied after upgrading to ZCS v10.1.19.

For customers upgrading from ZCS 10.0.x, 9.0.x, or 8.8.15, please follow the updated SNMP mitigation steps provided in the Security Advisory after completing the upgrade. If you have any questions or require assistance with the mitigation, please raise a Support ticket.

Security Fixes

Summary CVE-ID CVSS Score
Fixed a stored cross-site scripting (XSS) vulnerability in the Classic Web Client where crafted emails could execute malicious script in a user's session.

Packages

The package lineup for this release is:

zimbra-patch                                      ->  10.1.19.1783177840-2
zimbra-mbox-webclient-war                         ->  10.1.19.1783175257-1

Patch Installation

Please refer to below link to install 10.1.19 (July 07 2026):

Patch Installation


Quick note: Open Source repo

The steps to download, build, and see our code via Github can be found here: https://github.com/Zimbra/zm-build

Jump to: navigation, search