Zimbra Releases/10.1.20

Zimbra Daffodil (v10.1.20) Patch Release

Release Date: July 20, 2026

Security Fixes

Summary
Fixed a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.
Fixed a stored cross-site scripting (XSS) vulnerability in the Classic Web Client that could allow malicious attachment filenames to execute script under specific conditions.
Fixed a stored cross-site scripting (XSS) vulnerability in the Classic Web Client where crafted fields could execute malicious script under specific conditions.
Fixed a stored cross-site scripting (XSS) vulnerability in the Classic Web Client where a crafted field could execute malicious script when rendered.
Fixed a stored cross-site scripting (XSS) vulnerability in the Classic Web Client where crafted attachments could execute malicious script when rendered.
Fixed a mail forwarding restriction bypass that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.
Fixed a security issue in the EWS extension related to access controls.
Fixed an authorization issue in mailbox delegation.
Fixed a server-side request forgery (SSRF) vulnerability in the Nextcloud integration.

Note: Information disclosure is limited for security vulnerability fixes.

Fixed Issues

Licensing

  • Fixed an issue where using "Reset to COS Value" at the account level incorrectly reset the feature usage count to 0 instead of properly adjusting it based on the COS-inherited value.

Zimbra Collaboration

  • The issue where admin-configured mail redirects via zimbraAdminSieveScriptBefore/zimbraAdminSieveScriptAfter were blocked when zimbraFeatureMailForwardingInFiltersEnabled was set to FALSE has been resolved. Previously, this attribute incorrectly suppressed admin-level sieve redirects as well as user-level ones, causing forwarded mail to land in the recipient's INBOX instead of being redirected. With this fix, only user-created redirect filters are blocked when the attribute is FALSE; admin sieve script redirects now always execute as intended, regardless of the setting. Behavior when the attribute is set to TRUE remains unchanged, preserving backward compatibility.

Packages

The package lineup for this release is:

zimbra-patch                                      ->  10.1.20.1783418035-2 
zimbra-lds-patch                                  ->  10.1.20.1783352356-1 
zimbra-mta-patch                                  ->  10.1.20.1783342495-1 
zimbra-onlyoffice-patch                           ->  10.1.20.1783342495-1 
zimbra-proxy-patch                                ->  10.1.20.1783342495-1 
zimbra-ldap-patch                                 ->  10.1.20.1783342495-1 
zimbra-license-tools                              ->  10.1.20.1783085016-1 
zimbra-mbox-ews-service                           ->  10.1.20.1783080367-1 
zimbra-common-core-jar                            ->  10.1.20.1783079738-1 
zimbra-mbox-webclient-war                         ->  10.1.20.1783414027-1 
zimbra-zimlet-nextcloud-talk                      ->  1.0.0.1783340727-1 
zimbra-zimlet-nextcloud                           ->  1.0.17.1783343498-1

Patch Installation

Please refer to below link to install 10.1.20 (July 20 2026):

Patch Installation

Quick note: Open Source repo

The steps to download, build, and see our code via Github can be found here: https://github.com/Zimbra/zm-build

Jump to: navigation, search