Zimbra Releases/9.0.0/P46
Zimbra Collaboration Kepler 9.0.0 Patch 46 GA Release
Release Date: June 18, 2025
Check out the Security Fixes for this version of Zimbra Collaboration.
Please refer to the Patch Installation page for Patch Installation instructions.
As always, you are encouraged to tell us what you think in the Forums or open a support ticket to report issues
End of Life (EOL) Notice - ZCS 9.0
ZCS 9.0 is set to reach its End of Life on June 30, 2025. No further updates will be provided after this date. Customers using these versions are advised to plan their migration to the 10.1 version to ensure continued security updates and access to the latest features.
For assistance during this transition, our support team is available to address any inquiries.
10.1 is the active and supported version.
Things to know before you upgrade
Changes to SOAP API
There are changes in ChangePassword SOAP API. Please refer to API reference documentation. If you have custom auth implementation with ChangePassword, please incorporate changes to support new API changes.
Security Fixes
Summary | CVE-ID | CVSS Score |
---|---|---|
Addressed a denial of service (DoS) vulnerability in the admin console that could lead to service disruptions. | CVE-2025-53645 | |
This patch fixes a critical security vulnerability related to stored cross-site scripting in the Zimbra Classic Web Client. The fix strengthens input sanitization and enhances security. All customers are strongly advised to upgrade to this latest patch version immediately. | CVE-2025-27915 |
Packages
The package lineup for this release is:
zimbra-patch -> 9.0.0.1749649572.p46-2 zimbra-mbox-admin-console-war -> 9.0.0.1749644337-1 zimbra-mbox-webclient-war -> 9.0.0.1749617601-1
Patch Installation
Please refer to below link to install Kepler 9.0.0 Patch 46 (June 18 2025):
- Current patch packages are only applicable for mailstore nodes.
Quick note: Open Source repo
The steps to download, build, and see our code via Github can be found here: https://github.com/Zimbra/zm-build