<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Zimbra : Blog</title>
	<atom:link href="https://blog.zimbra.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.zimbra.com/</link>
	<description>All Things Zimbra</description>
	<lastBuildDate>Thu, 24 Sep 2026 08:53:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>
	<item>
		<title>What&#8217;s New in Zimbra 10.1.21 (Daffodil)</title>
		<link>https://blog.zimbra.com/2026/09/whats-new-in-zimbra-10-1-21-daffodil/</link>
					<comments>https://blog.zimbra.com/2026/09/whats-new-in-zimbra-10-1-21-daffodil/#respond</comments>
		
		<dc:creator><![CDATA[marilyn lee]]></dc:creator>
		<pubDate>Thu, 24 Sep 2026 08:53:50 +0000</pubDate>
				<category><![CDATA[Product News]]></category>
		<category><![CDATA[Patch Release]]></category>
		<category><![CDATA[Product Updates]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14444</guid>

					<description><![CDATA[<p>For over two decades, Zimbra has powered mission-critical communications for organizations across the globe — 200 million+ mailboxes, 6,000+ deployments, 140+ countries, and a worldwide network of dedicated partners. That scale is built on platform stability. But at Zimbra, stability has never meant standing still; and every release proves it. Zimbra Collaboration Suite v10.1.21 (Daffodil), [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2026/09/whats-new-in-zimbra-10-1-21-daffodil/">What&#8217;s New in Zimbra 10.1.21 (Daffodil)</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>For over two decades, Zimbra has powered mission-critical communications for organizations across the globe — 200 million+ mailboxes, 6,000+ deployments, 140+ countries, and a worldwide network of dedicated partners. That scale is built on platform stability. But at Zimbra, stability has never meant standing still; and every release proves it.</p>
<p><strong>Zimbra Collaboration Suite v10.1.21 (Daffodil)</strong>, available <strong>September 24, 2026</strong>, brings meaningful workspace innovations that make enterprise collaboration faster, smarter, and more personal. It also closes active security vulnerabilities that no production environment should carry unpatched. And with over 50 platform fixes, it ensures the infrastructure underneath performs as reliably as the teams depending on it.</p>
<p>Here is everything included in this release.</p>
<hr />
<h3><span style="text-decoration: underline;">Three Features That Change How Teams Work </span></h3>
<p><strong>1. Mail Recall &#8211; Because Mistakes Happen</strong></p>
<p><a href="https://blog.zimbra.com/wp-content/uploads/2026/09/Mail-recall-scaled.png" rel="shadowbox[sbpost-14444];player=img;"><img loading="lazy" decoding="async" class="alignnone wp-image-14448 size-large" src="https://blog.zimbra.com/wp-content/uploads/2026/09/Mail-recall-1024x591.png" alt="Mail Recall in action - Modern Web App" width="1024" height="591" srcset="https://blog.zimbra.com/wp-content/uploads/2026/09/Mail-recall-1024x591.png 1024w, https://blog.zimbra.com/wp-content/uploads/2026/09/Mail-recall-300x173.png 300w, https://blog.zimbra.com/wp-content/uploads/2026/09/Mail-recall-768x443.png 768w, https://blog.zimbra.com/wp-content/uploads/2026/09/Mail-recall-1536x887.png 1536w, https://blog.zimbra.com/wp-content/uploads/2026/09/Mail-recall-2048x1182.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></p>
<p><span data-contrast="auto">Enterprise teams send thousands of emails every day. The moment a mis-sent draft or wrong-recipient message leaves an outbox, the clock starts ticking. Until now, there was no clean way to stop it.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Zimbra 10.1.21 introduces native </span><b><span data-contrast="auto">Mail Recall</span></b><span data-contrast="auto"> in both the Modern Web App and Zimbra Desktop.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Sent internal messages can now be recalled within a configurable time window. The message is removed cleanly from the recipient&#8217;s inbox, and an automatic status notification confirms the recall is complete — giving users peace of mind and immediate control over accidental mis-sends.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">It is a focused workflow improvement with an outsized impact on how confidently and safely teams communicate every day.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p>&nbsp;</p>
<p><strong>2. Revamped Language Module — Enterprise Collaboration Without Borders</strong></p>
<p><a href="https://blog.zimbra.com/wp-content/uploads/2026/09/Bahasa-Indonesia-Translation-scaled.png" rel="shadowbox[sbpost-14444];player=img;"><img loading="lazy" decoding="async" class="alignnone wp-image-14449 size-large" src="https://blog.zimbra.com/wp-content/uploads/2026/09/Bahasa-Indonesia-Translation-1024x591.png" alt="Modern Web App UI in Bahasa Indonesia" width="1024" height="591" srcset="https://blog.zimbra.com/wp-content/uploads/2026/09/Bahasa-Indonesia-Translation-1024x591.png 1024w, https://blog.zimbra.com/wp-content/uploads/2026/09/Bahasa-Indonesia-Translation-300x173.png 300w, https://blog.zimbra.com/wp-content/uploads/2026/09/Bahasa-Indonesia-Translation-768x443.png 768w, https://blog.zimbra.com/wp-content/uploads/2026/09/Bahasa-Indonesia-Translation-1536x886.png 1536w, https://blog.zimbra.com/wp-content/uploads/2026/09/Bahasa-Indonesia-Translation-2048x1182.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></p>
<p><span data-contrast="auto">Great software is only as effective as the language it speaks. For global teams, an interface that feels imprecise or awkward in their primary language introduces subtle friction every single workday.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">In Zimbra 10.1.21, our engineering team conducted a comprehensive, proactive review of the entire Modern Web App localization framework — </span><i><span data-contrast="auto">updating over 6,000 UI translation phrases</span></i><b><i><span data-contrast="auto"> </span></i></b><span data-contrast="auto">across the interface and addressing more than </span><i><span data-contrast="auto">50 direct customer-reported translation requests</span></i><b><i><span data-contrast="auto">. </span></i></b><span data-contrast="auto">As a result, everything on your screen feels authentically local, not merely translated.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Beyond accuracy, Zimbra 10.1.21 also adds </span><i><span data-contrast="auto">native language support for Bahasa Indonesia and Filipino (Tagalog)</span></i><b><i><span data-contrast="auto">,</span></i></b><span data-contrast="auto"> extending the platform&#8217;s reach to enterprise teams across Southeast Asia who can now work in their primary language from day one — and experience Zimbra the way it was always meant to feel.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p>&nbsp;</p>
<p><strong>3. <span class="TextRun MacChromeBold SCXW26801250 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="none"><span class="NormalTextRun SCXW26801250 BCX0" data-ccp-parastyle="heading 3">Per-Domain IdP &amp; SAML Routing — Identity Management at Scale</span></span><span class="EOP Selected SCXW26801250 BCX0" data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:240}"> </span></strong></p>
<p><a href="https://blog.zimbra.com/wp-content/uploads/2026/09/global_settings_saml_sso.png" rel="shadowbox[sbpost-14444];player=img;"><img loading="lazy" decoding="async" class="alignnone wp-image-14450 size-large" src="https://blog.zimbra.com/wp-content/uploads/2026/09/global_settings_saml_sso-1024x640.png" alt="Admin Console SAML Setup Wizard — domain configuration screen" width="1024" height="640" srcset="https://blog.zimbra.com/wp-content/uploads/2026/09/global_settings_saml_sso-1024x640.png 1024w, https://blog.zimbra.com/wp-content/uploads/2026/09/global_settings_saml_sso-300x188.png 300w, https://blog.zimbra.com/wp-content/uploads/2026/09/global_settings_saml_sso-768x480.png 768w, https://blog.zimbra.com/wp-content/uploads/2026/09/global_settings_saml_sso-1536x960.png 1536w, https://blog.zimbra.com/wp-content/uploads/2026/09/global_settings_saml_sso.png 1920w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></p>
<p><span data-contrast="auto">Organizations running multiple business units, customer brands, or managed tenants on a shared Zimbra environment have historically faced friction around authentication. A single shared Identity Provider meant shared configuration risk and the constant threat of cross-domain SSO conflicts.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Zimbra 10.1.21 solves this cleanly.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">Administrators can now assign a distinct Identity Provider to each domain. Users are automatically routed to their domain&#8217;s designated IdP at login, with fully isolated authentication metadata per domain — no configuration collisions, no cross-tenant leakage.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">And for the first time, none of this requires editing configuration files at the command line. A new </span><i><span data-contrast="auto">point-and-click SAML Setup Wizard in the Admin Console</span></i><span data-contrast="auto"> makes domain-level authentication accessible to any administrator. IdP metadata import, certificate management, and domain authentication configuration are handled entirely through a clean graphical interface — no server access required.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">For MSPs and hosting partners managing multiple client tenants, this is a significant operational unlock that removes a longstanding complexity barrier.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p>&nbsp;</p>
<hr />
<h3><span style="text-decoration: underline;">More in This Release: Everyday Enhancements That Add Up</span></h3>
<p><span class="TextRun SCXW91189476 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="auto"><span class="NormalTextRun SCXW91189476 BCX0" data-ccp-parastyle="Normal (Web)">Alongside the three headline features, Zimbra 10.1.21 delivers a focused set </span></span><span class="TextRun SCXW91189476 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="auto"><span class="NormalTextRun SCXW91189476 BCX0" data-ccp-parastyle="Normal (Web)">of workflow improvements for users and administrators across the platform:</span></span><span class="EOP Selected SCXW91189476 BCX0" data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<table style="width: 100%; border-collapse: collapse; font-family: Arial,sans-serif; font-size: 15px; line-height: 1.5;">
<thead>
<tr style="background-color: #f2f4f7;">
<th style="padding: 14px; border: 1px solid #d9d9d9; text-align: left; vertical-align: top;">Enhancement</th>
<th style="padding: 14px; border: 1px solid #d9d9d9; text-align: left; vertical-align: top;">Who It&#8217;s For</th>
<th style="padding: 14px; border: 1px solid #d9d9d9; text-align: left; vertical-align: top;">What It Does</th>
</tr>
</thead>
<tbody>
<tr>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;"><strong>Self-Service Account Clean Up</strong></td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">All Users</td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">Sort emails by size, view storage breakdowns, and bulk-delete to manage mailbox quota without raising an IT ticket.</td>
</tr>
<tr style="background-color: #fafafa;">
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;"><strong>Inline Quick Reply &amp; Message Redirect</strong></td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">All Users</td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">Reply within conversation threads without losing context; resend messages to new recipients while preserving original sender address and formatting.</td>
</tr>
<tr>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;"><strong>Density Modes &amp; Keyboard Navigation</strong></td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">Power Users</td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">Relaxed, Regular, or Slim inbox view modes, and use arrow-key navigation across message lists with the preview pane on or off.</td>
</tr>
<tr style="background-color: #fafafa;">
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;"><strong>Side-by-Side Multi-Calendar View</strong></td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">All Users</td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">Align multiple personal and shared calendars in Day view with independent color coding and synchronized time slots.</td>
</tr>
<tr>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;"><strong>Guided First-Time App Tour</strong></td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">New Employees</td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">An interactive onboarding walkthrough introducing essential webmail features at first login; restartable from Settings at any time.</td>
</tr>
<tr style="background-color: #fafafa;">
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;"><strong>Default Email Templates</strong></td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">All Users</td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">Pre-written message templates now enabled by default during email composition; manageable at admin or individual user level.</td>
</tr>
<tr>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;"><strong>Full-Chain S/MIME Validation</strong></td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">Security Teams</td>
<td style="padding: 14px; border: 1px solid #d9d9d9; vertical-align: top;">Signed outbound emails automatically include intermediate certificate chains, eliminating trust validation errors at recipient mail clients.</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<hr />
<h3><span style="text-decoration: underline;">Security Hardening: High-Priority Platform Defence </span></h3>
<p>Z<span data-contrast="auto">imbra 10.1.21 includes essential security updates addressing account protection, remote authentication, web client safeguards, and core runtime components. </span><b><span data-contrast="auto">Environments running unpatched versions carry unmitigated security risks, and administrators are strongly advised to apply this release immediately.</span></b><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">To protect active deployments while giving IT teams clear visibility into risk areas, key fixes in this release address:</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="21" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Account Recovery &amp; Identity Workflows:</span></b><span data-contrast="auto"> Neutralizes security flaws within self-service password recovery logic that exposed user accounts to unauthorized access.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="21" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">WebDAV Remote Access &amp; MFA Enforcement:</span></b><span data-contrast="auto"> Corrects pre-MFA session validation logic, strictly requiring full multi-factor authentication completion before granting WebDAV endpoint access.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="21" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">Classic Web Client Safeguards:</span></b><span data-contrast="auto"> Resolves stored cross-site scripting (XSS) vectors in the Classic Web Client to prevent malicious script execution via crafted email content.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="21" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><b><span data-contrast="auto">Core Runtime &amp; Infrastructure:</span></b><span data-contrast="auto"> Upgrades the underlying execution environment to OpenJDK 17.0.19 and refreshes web server cryptographic modules.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
</ul>
<p>&nbsp;</p>
<hr />
<h3><span style="text-decoration: underline;">Platform Stability: 50+ Fixes Across the Stack</span></h3>
<p><span data-contrast="auto">Reliable daily operations depend on what happens beneath the surface. Zimbra 10.1.21 resolves over 50 targeted issues across connectors, server infrastructure, and webmail:</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Zimbra Connector for Outlook (ZCO)</span></b><br />
Outlook no longer faces stability issues during two-factor device re-validation or when authentication attributes are empty. MIME boundary parsing has been corrected so complex email attachments always render in full. Domain password expiration now triggers an explicit credential prompt in Outlook rather than silent send/receive failure. Oversized attachment bundles are handled cleanly with a dedicated notification dialog that identifies the offending files.</li>
<li><b><span data-contrast="auto">Server Operations and Storage</span></b><br />
An IMAP socket resource leak triggered by out-of-bounds fetch requests, including Apple Mail on iOS 18, has been resolved, preventing mailbox locking and preserving server memory. An automated daily background utility now clears accumulated temporary processing files at 1:00 AM server time, preventing disk space inflation over time. System-wide validation now blocks email forwarding rules that target a user&#8217;s own address or alias, eliminating accidental mail loop conditions. Large account deletions are handled more safely, with directory cleanup deferred until mailbox purges are fully complete.</li>
<li><b><span data-contrast="auto">Webmail, Shared Folders, and Licensing</span></b><br />
Users can now move and delete messages within individually mounted shared folders. Deleting items from a shared folder correctly places a copy in the user&#8217;s own Trash, consistent with expected behavior across all clients. Cross-interface signature editing inconsistencies, saved search sorting, print preview freezing, folder hierarchy display in move dialogs, and external address book autocomplete have all been resolved. License accounting now correctly handles full inheritance chains for domain default configurations, and outbound license communications support HTTP/HTTPS proxy routing.</li>
</ul>
<hr />
<h3><span style="text-decoration: underline;"><span class="TextRun MacChromeBold SCXW95620888 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="none"><span class="NormalTextRun SCXW95620888 BCX0" data-ccp-parastyle="heading 2">Four Reasons to Upgrade to 10.1.21</span></span><span class="EOP Selected SCXW95620888 BCX0" data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:240}"> </span></span></h3>
<p><b><span data-contrast="auto">1. A platform that keeps getting better</span></b><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559685&quot;:360,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;469777462&quot;:[720,360],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[0,8]}"> </span></p>
<p>From user control innovations like Mail Recall and Self-Service Storage Cleanup to Modern Web App refinements side-by-side calendar views, density modes, inline replies, a guided onboarding tour, and 6,000+ translation fixes with native Bahasa Indonesia and Tagalog support, every release makes daily email and collaboration smoother, more responsive, and more capable.</p>
<p><b><span data-contrast="auto">2. Enterprise identity, simplified</span></b><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559685&quot;:360,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;469777462&quot;:[720,360],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[0,8]}"> </span></p>
<p>Per-Domain IdP &amp; SAML Routing gives each domain its own Identity Provider with isolated authentication metadata to eliminate cross-tenant SSO conflicts. The new Admin Console SAML Setup Wizard lets administrators handle domain SAML configuration, metadata imports, and certificates entirely through a point-and-click UI with no manual configuration files required.</p>
<p><b><span data-contrast="auto">3. Proactive Security hardening included</span></b><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559685&quot;:360,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;469777462&quot;:[720,360],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[0,8]}"> </span></p>
<p>Delivers urgent security patches for self-service account recovery, WebDAV MFA enforcement, Classic Web Client XSS safeguards and OpenJDK 17.0.19. Unpatched environments carry documented risk and should upgrade immediately.</p>
<p><strong>4. <span class="TextRun MacChromeBold SCXW53034443 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="auto"><span class="NormalTextRun SCXW53034443 BCX0" data-ccp-charstyle="Strong">Platform stability and operational confidence</span></span><span class="EOP Selected SCXW53034443 BCX0" data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559685&quot;:360,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;469777462&quot;:[720,360],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[0,8]}"> </span> </strong></p>
<p>Over 50 targeted fixes across Outlook connectors (ZCO), IMAP server operations, shared folder workflows, and automated disk cleanup ensure the predictable, dependable performance enterprise operations require.</p>
<p>&nbsp;</p>
<hr />
<h3><span style="text-decoration: underline;"><span class="TextRun MacChromeBold SCXW232770429 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="none"><span class="NormalTextRun SCXW232770429 BCX0" data-ccp-parastyle="heading 2">Upgrade to Zimbra 10.1.21</span></span><span class="EOP Selected SCXW232770429 BCX0" data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:240}"> </span></span></h3>
<p><span class="TextRun SCXW88809172 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="auto"><span class="NormalTextRun SCXW88809172 BCX0" data-ccp-parastyle="Normal (Web)">Zimbra 10.1.21 is recommended as a </span></span><strong><span class="TextRun MacChromeBold SCXW88809172 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="auto"><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW88809172 BCX0" data-ccp-charstyle="Strong">High Priority</span></span></strong><span class="TextRun SCXW88809172 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="auto"><span class="NormalTextRun SCXW88809172 BCX0" data-ccp-parastyle="Normal (Web)"> upgrade given the security and stability improvements included in this release. Validating the update in a staging environment prior to production deployment is recommended.</span></span><span class="EOP Selected SCXW88809172 BCX0" data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></p>
<p><a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.21">Read the Full Release Notes →</a><br />
<a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.0/patch_installation">Patch Installation Guide →</a><br />
<a href="https://support.zimbra.com/s/login/">Contact Zimbra Support →</a></p>
<p>The post <a href="https://blog.zimbra.com/2026/09/whats-new-in-zimbra-10-1-21-daffodil/">What&#8217;s New in Zimbra 10.1.21 (Daffodil)</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.zimbra.com/2026/09/whats-new-in-zimbra-10-1-21-daffodil/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>When email becomes a sovereignty decision</title>
		<link>https://blog.zimbra.com/2026/09/when-email-becomes-a-sovereignty-decision/</link>
					<comments>https://blog.zimbra.com/2026/09/when-email-becomes-a-sovereignty-decision/#respond</comments>
		
		<dc:creator><![CDATA[Annaig Vigouroux]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 02:50:45 +0000</pubDate>
				<category><![CDATA[Data Sovereignty]]></category>
		<category><![CDATA[Thought Leadership]]></category>
		<category><![CDATA[Microsoft Exchange Alternatives]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14428</guid>

					<description><![CDATA[<p>For most of the last decade, enterprise procurement has run on autopilot. A requirement comes up, a shortlist forms, and one of a handful of familiar names, often Microsoft, usually wins by default. Familiarity and perceived low risk have done a lot of the deciding.  That&#8217;s starting to change. In a recent piece for IT Europa, Zimbra CRO [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2026/09/when-email-becomes-a-sovereignty-decision/">When email becomes a sovereignty decision</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">For most of the last decade, enterprise procurement has run on autopilot. A requirement comes up, a shortlist forms, and one of a handful of familiar names, often Microsoft, usually wins by default. Familiarity and perceived low risk have done a lot of the deciding.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto">That&#8217;s starting to change. In a recent piece for IT Europa, Zimbra CRO Anthony Chadd pointed to a real shift underway: procurement teams are asking harder questions about flexibility, data residency, and long-term control, not just cost and functionality. France&#8217;s move to reduce reliance on proprietary desktop software and Schleswig-Holstein&#8217;s push toward digital independence are two visible public-sector signals. Wire&#8217;s State of Digital Sovereignty 2025 report backs this up with numbers: 63.2% of respondents now consider open-source software critical to their sovereignty strategy, 47.4% see reducing dependency on US technology vendors as a strategic imperative, and 36.8% now treat EU data hosting as a real procurement factor.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto"> </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><b><span data-contrast="auto">Why email is the flashpoint</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto">Email is usually the last thing anyone questions. It&#8217;s treated as a utility, not a decision. That&#8217;s exactly why it&#8217;s become such a clear test case for this shift. The questions procurement teams are now asking, where does our data actually sit, does our hosting align with sovereignty requirements we&#8217;re on the hook for, are we locked into one vendor&#8217;s ecosystem by default, didn&#8217;t used to come up in an email RFP. Now they do.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto">For organizations in the EU, this isn&#8217;t an abstract compliance exercise. The US CLOUD Act allows US jurisdiction to reach data stored by US-headquartered providers regardless of where that data physically sits. That&#8217;s a real gap for any organization relying on Microsoft 365&#8217;s EU data-residency options as a sovereignty answer. Data residency and data sovereignty are not the same thing, and the difference matters most in exactly the systems, like email, that everyone assumed were settled.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto"> </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><b><span data-contrast="auto">A live example, not a hypothetical</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto"><a href="https://www.zimbra.com/industry-case-study/ensuring-digital-sovereignty-cost-efficiency-how-sitiv-delivers-secure-collaboration-with-zimbra/">SITIV</a>, the French public IT services operator, is a case in point. Rather than defaulting to Microsoft, SITIV reassessed its messaging platform against sovereignty and governance requirements for a user base north of 30,000 across the public sector. The result: full control over data jurisdiction, resilience at scale, and lower licensing and maintenance costs as a byproduct, not the starting point.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto"> </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><b><span data-contrast="auto">Where this leaves procurement teams</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto">Nobody&#8217;s arguing for a return to fragmented, best-of-breed chaos. What&#8217;s changing is the assumption that one integrated ecosystem should own every workload by default. The organizations getting this right are the ones preserving choice deliberately, on jurisdiction, on deployment model, on which vendor sits behind a system as foundational as email, rather than inheriting that choice from whichever platform won everything else.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto"> </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto">That&#8217;s the case for evaluating deployment flexibility, data sovereignty, and privacy as procurement criteria in their own right, not nice-to-haves bundled into a bigger platform decision.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto">  </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="auto">Source: Anthony Chadd, &#8220;Are customers more willing to challenge &#8216;Microsoft by default&#8217; procurement?&#8221;, IT Europa, July 2026.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}"> </span></p>
<p>The post <a href="https://blog.zimbra.com/2026/09/when-email-becomes-a-sovereignty-decision/">When email becomes a sovereignty decision</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.zimbra.com/2026/09/when-email-becomes-a-sovereignty-decision/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Patch Release Update: Zimbra 10.1.20</title>
		<link>https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/</link>
		
		<dc:creator><![CDATA[marilyn lee]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 09:15:40 +0000</pubDate>
				<category><![CDATA[Product News]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14414</guid>

					<description><![CDATA[<p>Patch Security Severity: High  Deployment Risk: Low We have released Zimbra Collaboration Suite (ZCS) v10.1.20. This release contains fixes for multiple critical security issues including a permanent fix for the critical SNMP vulnerability disclosed in our recent security advisory. The release also includes bug fixes in licensing and mail filtering. Zimbra 10.1.20 (Release Notes) We strongly [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/">Patch Release Update: Zimbra 10.1.20</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><strong>Patch Security Severity: </strong><strong><span style="color: #ff0201;">High </span></strong></h3>
<h3><strong>Deployment Risk: </strong><strong><span style="color: #339966;">Low</span></strong></h3>
<hr />
<p>We have released Zimbra Collaboration Suite (ZCS) v10.1.20.</p>
<p>This release contains fixes for multiple critical security issues including a permanent fix for the critical SNMP vulnerability disclosed in our recent security advisory. The release also includes bug fixes in licensing and mail filtering.</p>
<ul>
<li><a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20">Zimbra 10.1.20 (Release Notes)</a></li>
</ul>
<p>We strongly recommend upgrading to this version to keep your environment secure.</p>
<hr />
<h3><span style="text-decoration: underline;">Critical Security Fixes</span></h3>
<p>The following issues are fixed in this release:</p>
<ul>
<li>A command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. (Permanent fix for the vulnerability disclosed in our security advisory on 26th June 2026)</li>
<li>A stored cross-site scripting (XSS) vulnerability in the Classic Web Client that could allow malicious attachment filenames to execute script under specific conditions.</li>
<li>A XSS vulnerability in the Classic Web Client where crafted fields could execute malicious script under specific conditions.</li>
<li>A XSS vulnerability in the Classic Web Client where a crafted field could execute malicious script when rendered.</li>
<li>A XSS vulnerability in the Classic Web Client where crafted attachments could execute malicious script when rendered.</li>
<li>A mail forwarding restriction bypass that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.</li>
<li>A security issue in the EWS extension related to access controls.</li>
<li>An authorization issue in mailbox delegation.</li>
<li>A server-side request forgery (SSRF) vulnerability in the Nextcloud integration.</li>
</ul>
<p><em><span style="font-weight: bold;">Note:</span> In line with industry best practices, information disclosure is limited for security vulnerability fixes. </em></p>
<p>&nbsp;</p>
<h3><span style="text-decoration: underline;">Other Bug Fixes</span></h3>
<ul style="list-style-type: disc;">
<li><strong><span style="color: #595959; line-height: 24.5333px;">Licensing:</span></strong><span style="color: #595959; line-height: 24.5333px;"> Corrected &#8220;Reset to COS Value&#8221; so feature usage counts restore correctly instead of resetting to zero.</span></li>
<li><strong><span style="color: #595959; line-height: 24.5333px;">Mail Forwarding:</span></strong><span style="color: #595959; line-height: 24.5333px;"> Fixed admin mail redirects being blocked when user forwarding restrictions are switched on under very specific conditions.</span></li>
</ul>
<hr />
<p>If you require assistance applying the new patch or have concerns regarding potential exposure, please raise a support ticket <a href="https://support.zimbra.com/s/login/?" rel="noopener">here</a>.</p>
<p>The post <a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/">Patch Release Update: Zimbra 10.1.20</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Patch Release Update: Zimbra 10.1.19</title>
		<link>https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/</link>
		
		<dc:creator><![CDATA[marilyn lee]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 04:53:52 +0000</pubDate>
				<category><![CDATA[Product News]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14409</guid>

					<description><![CDATA[<p>Patch Security Severity: High  Deployment Risk: Low We have released Zimbra 10.1.19 to address a critical security vulnerability which impacts the Classic Web Client: Zimbra 10.1.19 (Release Notes) We strongly recommend upgrading to this version to keep your environment secure. Any customer using the Classic Web Client should upgrade to ZCS v10.1.19 as soon as possible, [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/">Patch Release Update: Zimbra 10.1.19</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><strong>Patch Security Severity: </strong><strong><span style="color: #ff0201;">High </span></strong></h3>
<h3><strong>Deployment Risk: </strong><strong><span style="color: #339966;">Low</span></strong></h3>
<hr />
<p>We have released Zimbra 10.1.19 to address a critical security vulnerability which impacts the Classic Web Client:</p>
<ul>
<li><a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.19">Zimbra 10.1.19 (Release Notes)</a></li>
</ul>
<p>We strongly recommend upgrading to this version to keep your environment secure.</p>
<hr />
<p><span style="font-weight: bold;">Any customer using the Classic Web Client should upgrade to ZCS v10.1.19 as soon as possible, as this issue only impacts the users of Classic Web Client. </span></p>
<p>The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened. If exploited, it could allow access to mailbox information, session data, or account settings.</p>
<p>We strongly recommend all customers to upgrade to ZCS v10.1.19 to ensure they have received the latest security patches, bug fixes, and enhancements.</p>
<hr />
<p>If you require assistance applying these mitigations or have concerns regarding potential exposure, please raise a support ticket <a href="https://support.zimbra.com/s/login/?" rel="noopener">here</a>.</p>
<p>The post <a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/">Patch Release Update: Zimbra 10.1.19</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Patch Release Update: Zimbra 10.1.17</title>
		<link>https://blog.zimbra.com/2026/05/patch-release-update-zimbra-10-1-17/</link>
		
		<dc:creator><![CDATA[marilyn lee]]></dc:creator>
		<pubDate>Thu, 28 May 2026 09:31:58 +0000</pubDate>
				<category><![CDATA[Product News]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14378</guid>

					<description><![CDATA[<p>Patch Security Severity: Medium  Deployment Risk: Low We have released Zimbra Version 10.1.17, bringing meaningful improvements across the Modern WebClient — from how you compose and read email to how you schedule meetings — along with fixes for ZCO, mobile, and server components, and several important security patches your teams should be aware of. Zimbra 10.1.17 [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2026/05/patch-release-update-zimbra-10-1-17/">Patch Release Update: Zimbra 10.1.17</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><strong>Patch Security Severity: </strong><strong><span style="color: #ff9900;">Medium </span></strong></h3>
<h3><strong>Deployment Risk: </strong><strong><span style="color: #339966;">Low</span></strong></h3>
<hr />
<p>We have released Zimbra Version 10.1.17, bringing meaningful improvements across the Modern WebClient — from how you compose and read email to how you schedule meetings — along with fixes for ZCO, mobile, and server components, and several important security patches your teams should be aware of.</p>
<ul>
<li><a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.17">Zimbra 10.1.17 (Release Notes)</a></li>
</ul>
<p>We strongly recommend all admins and users to upgrade for improved stability and enhanced email compatibility.</p>
<hr />
<h2><strong>What&#8217;s New in 10.1.17</strong></h2>
<ul>
<li><strong>Voice Composer for Email:</strong> Dictate emails hands-free with system language detection and spoken punctuation — available in new, reply, and forward views. Enabled by admins via the voice-composer Zimlet.</li>
<li><strong>Smarter Calendar Scheduling:</strong> A redesigned event creation flow reduces scrolling for quicker scheduling. The new &#8220;Suggest a Time&#8221; feature shows participant availability and recommends optimal meeting slots as attendees are added.</li>
<li><strong>Enhanced Email Experience:</strong> View the latest emails first with a new thread order setting. Attachments are pinned to a dedicated top panel in thread view, and the composer now supports drag-and-drop attachments, multi-signature, and autosave with a cleaner layout.</li>
<li><strong>2FA on Login Page:</strong> QR code now shown directly at login when 2FA is enforced, removing the need to visit preferences first.</li>
<li><strong>Desktop App Upgraded:</strong> Electron updated from 37 to 41, bringing improved security, performance, and compatibility with newer Chromium and Node.js versions.</li>
<li><strong>Ubuntu 24:</strong> Now fully supported as a GA release.</li>
</ul>
<hr />
<div>
<h2><strong>Security Patches</strong></h2>
</div>
<div>
<ul>
<li><span style="font-weight: bold;">Delegated Send Hardened:</span> Fixed an authorization bypass that could allow authenticated users to send emails impersonating other users.</li>
<li><span style="font-weight: bold;">Classic UI Attachment Preview Secured:</span> Fixed a stored XSS vulnerability where malicious email attachments could execute scripts when previewed.</li>
<li><span style="font-weight: bold;">LFI Vulnerabilities Patched: </span>Closed both an authenticated LFI in Briefcase via the packages parameter, and an unauthenticated LFI in Classic UI via the fu parameter.</li>
<li><span style="font-weight: bold;">EWS Endpoint Protected:</span>Fixed a CSRF vulnerability that could allow unauthorized actions to be performed on behalf of authenticated users.</li>
<li><span style="font-weight: bold;">Document Editing Token Security Improved: </span>Fixed weak random number generation for zimbraDocumentEditingJwtSecret, which was susceptible to offline brute-force attacks.</li>
</ul>
<p><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a0.png" alt="⚠" class="wp-smiley" style="height: 1em; max-height: 1em;" /><span style="font-weight: bold;">  RHEL 9 and Ubuntu 22:</span> SSHA256 password hashes on these platforms may cause authentication failures after password changes or migrations. Reset affected user passwords post-upgrade to restore access — passwords generated after the fix will be created correctly.</p>
<hr />
<div data-hs-cos-general-type="widget" data-hs-cos-type="module">
<h2><strong>Key Bug &amp; Improvements</strong></h2>
</div>
<div data-hs-cos-general-type="widget" data-hs-cos-type="rich_text">
<ul>
<li><span style="font-weight: bold;">Mailbox Data Protected Post-migration: </span>zmpurgeoldmbox now safely skips blobs still referenced by active mailboxes, eliminating a data loss risk after mailbox migration.</li>
<li><span style="font-weight: bold;">Mailbox Quota Bypass via IMAP Copy to Trash: </span>A configurable soft limit keeps mailbox size in check, preventing unchecked growth from repeated IMAP copy operations.</li>
<li>Z<span style="font-weight: bold;">CO Delegated Send: </span>Emails sent via Send As are now correctly saved in the delegated account&#8217;s Sent folder, and forwarded messages preserve their original formatting.</li>
<li><span style="font-weight: bold;">Samsung Email:</span> Contacts sync now sync consistently for datasets over 1,000 contacts.</li>
<li><span style="font-weight: bold;">iOS Calendar: </span>Events stay visible after accepting an invite, even when auto-add invites is disabled. Responses are also correctly sent to the organizer now.</li>
<li><span style="font-weight: bold;">Mobile App: </span>Attachments in the Zimbra mobile app now download successfully without getting stuck.</li>
<li><span style="font-weight: bold;">Modern WebClient: </span>PDF multi-page preview, print (Ctrl+P), and local contact autocomplete all fixed.</li>
</ul>
</div>
<h3><span style="text-decoration: underline;"><strong>Additional Fixed Issues</strong></span></h3>
<ul>
<li>20+ additional fixes across Admin Console, Chat, ZCO, Backup, and Zimbra Desktop including filter rule duplication, search highlighting, keyboard shortcuts, Admin Console localisation, and chat performance.</li>
</ul>
<hr />
<h2><strong>Customer Feedback Portal</strong></h2>
</div>
<p>Vote on suggested features, propose your own and stay updated with our product roadmap. Join us at <a href="https://pm.zimbra.com/" rel="noopener">pm.zimbra.com</a>, our dedicated customer portal, for product feedback. Contribute to Zimbra&#8217;s evolution!</p>
<p>The post <a href="https://blog.zimbra.com/2026/05/patch-release-update-zimbra-10-1-17/">Patch Release Update: Zimbra 10.1.17</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Product Advisory: zmpurgeoldmbox May Delete External Storage Blobs After Mailbox Migration</title>
		<link>https://blog.zimbra.com/2026/03/product-advisory-zmpurgeoldmbox-may-delete-external-storage-blobs-after-mailbox-migration/</link>
		
		<dc:creator><![CDATA[marilyn lee]]></dc:creator>
		<pubDate>Fri, 27 Mar 2026 05:39:58 +0000</pubDate>
				<category><![CDATA[Product News]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14367</guid>

					<description><![CDATA[<p>Applies to: Zimbra Collaboration Suite 10.1.15, 10.1.16 with external object storage (Scality, S3, OpenIO)  Summary  A regression in ZCS 10.1.15 causes zmpurgeoldmbox to delete external blobs (Scality, S3, OpenIO) after mailbox migration, even when zimbraMailboxMoveSkipBlobs=TRUE.  This results in permanent, irrecoverable email data loss on the destination server.  A fix is targeted for the 10.1.17 patch release.  Until then, do not run zmpurgeoldmbox after mailbox migrations if you [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2026/03/product-advisory-zmpurgeoldmbox-may-delete-external-storage-blobs-after-mailbox-migration/">Product Advisory: zmpurgeoldmbox May Delete External Storage Blobs After Mailbox Migration</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em><span class="TextRun SCXW186258407 BCX0" lang="EN-IN" xml:lang="EN-IN" data-contrast="none"><span class="NormalTextRun SCXW186258407 BCX0"><strong>Applies to:</strong> Zimbra Collaboration Suite 10.1</span><span class="NormalTextRun SCXW186258407 BCX0">.</span><span class="NormalTextRun SCXW186258407 BCX0">15</span><span class="NormalTextRun SCXW186258407 BCX0">,</span><span class="NormalTextRun SCXW186258407 BCX0"> </span><span class="NormalTextRun SCXW186258407 BCX0">10.1.16</span><span class="NormalTextRun SCXW186258407 BCX0"> </span><span class="NormalTextRun SCXW186258407 BCX0">with external object storage (</span><span class="NormalTextRun SpellingErrorV2Themed SCXW186258407 BCX0">Scality</span><span class="NormalTextRun SCXW186258407 BCX0">, S3, </span><span class="NormalTextRun SpellingErrorV2Themed SCXW186258407 BCX0">OpenIO</span><span class="NormalTextRun SCXW186258407 BCX0">)</span></span><span class="EOP Selected SCXW186258407 BCX0" data-ccp-props="{&quot;335559739&quot;:80}"> </span></em></p>
<p><b><span data-contrast="none">Summary</span></b><span data-ccp-props="{&quot;335559739&quot;:40,&quot;335572079&quot;:6,&quot;335572080&quot;:1,&quot;335572081&quot;:15233818,&quot;469789806&quot;:&quot;single&quot;}"> </span></p>
<ul>
<li><span data-contrast="auto">A regression in ZCS 10.1.15 causes zmpurgeoldmbox to delete external blobs (Scality, S3, OpenIO) after mailbox migration, even when zimbraMailboxMoveSkipBlobs=TRUE.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li><span data-contrast="auto">This results in permanent, irrecoverable email data loss on the destination server.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li><span data-contrast="auto">A fix is targeted for the 10.1.17 patch release.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li><b><span data-contrast="auto">Until then, do not run zmpurgeoldmbox after mailbox migrations if you use external or unified object storage.</span></b><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
</ul>
<hr />
<p aria-level="1"><b><span data-contrast="none">What Happened</span></b><span data-ccp-props="{&quot;335559738&quot;:360,&quot;335559739&quot;:200}"> </span></p>
<p><span data-contrast="auto">In ZCS 9.0, running zmpurgeoldmbox after a zmmboxmove correctly cleaned up only local metadata (MySQL + Lucene indexes) on the source server, leaving external blobs untouched. In ZCS 10.1.15, a code change inadvertently altered the logic that identifies external/centralized storage. As a result:</span><span data-ccp-props="{&quot;335559739&quot;:160}"> </span></p>
<ul>
<li><span data-contrast="auto">zmpurgeoldmbox now deletes external blobs even without the &#8211;forceDeleteBlobs flag</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li><span data-contrast="auto">The destination server’s mailbox still references those deleted blobs</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li><span data-contrast="auto">Affected users see “missing blob” errors and lose access to their emails permanently</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
</ul>
<p aria-level="1"><b><span data-contrast="none">Am I Affected?</span></b><span data-ccp-props="{&quot;335559738&quot;:360,&quot;335559739&quot;:200}"> </span></p>
<p><span data-contrast="auto">You are affected if </span><b><span data-contrast="auto">all of the following</span></b><span data-contrast="auto"> are true:</span><span data-ccp-props="{&quot;335559739&quot;:160}"> </span></p>
<ol>
<li aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">You are running ZCS 10.1.15 or 10.1.16 </span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">You use external object storage (Scality, S3, OpenIO, or similar) as a primary or secondary (HSM) volume — especially with unified storage enabled</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">You perform mailbox migrations using zmmboxmove with blob-skipping attributes (zimbraMailboxMoveSkipBlobs=TRUE or zimbraMailboxMoveSkipHsmBlobs=TRUE)</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">You run zmpurgeoldmbox on the source server after migration</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
</ol>
<p><i><span data-contrast="none">If you use only local (internal) storage and no external object storage, this issue does not affect you.</span></i><span data-ccp-props="{&quot;335559738&quot;:160,&quot;335559739&quot;:160}"> </span></p>
<p aria-level="1"><b><span data-contrast="none">Behavior Comparison: ZCS 9.0 vs 10.1.15</span></b><span data-ccp-props="{&quot;335559738&quot;:360,&quot;335559739&quot;:200}"> </span></p>
<table data-tablestyle="MsoNormalTable" data-tablelook="1184" aria-rowcount="4">
<tbody>
<tr aria-rowindex="1">
<td data-celllook="69905"><b><span data-contrast="none">Scenario</span></b><span data-ccp-props="{}"> </span></td>
<td data-celllook="69905"><b><span data-contrast="none">ZCS 9.0</span></b><span data-ccp-props="{}"> </span></td>
<td data-celllook="69905"><b><span data-contrast="none">ZCS 10.1.15 (Bug)</span></b><span data-ccp-props="{}"> </span></td>
</tr>
<tr aria-rowindex="2">
<td data-celllook="4369"><span data-contrast="none">External/unified storage, no &#8211;forceDeleteBlobs</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="4369"><b><span data-contrast="none">Blobs preserved</span></b><span data-ccp-props="{}"> </span></td>
<td data-celllook="4369"><b><span data-contrast="none">Blobs DELETED</span></b><span data-ccp-props="{}"> </span></td>
</tr>
<tr aria-rowindex="3">
<td data-celllook="69905"><span data-contrast="none">External/unified storage, with &#8211;forceDeleteBlobs</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="69905"><b><span data-contrast="none">Blobs preserved *</span></b><span data-ccp-props="{}"> </span></td>
<td data-celllook="69905"><b><span data-contrast="none">Blobs DELETED</span></b><span data-ccp-props="{}"> </span></td>
</tr>
<tr aria-rowindex="4">
<td data-celllook="4369"><span data-contrast="none">Internal (local) storage only</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="4369"><span data-contrast="none">Blobs deleted (expected)</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="4369"><span data-contrast="none">Blobs deleted (expected)</span><span data-ccp-props="{}"> </span></td>
</tr>
</tbody>
</table>
<p><i><span data-contrast="none">* In ZCS 9.0, &#8211;forceDeleteBlobs was not implemented for external stores (Bug 96149). It is being properly implemented as part of the fix.</span></i><span data-ccp-props="{&quot;335559738&quot;:80,&quot;335559739&quot;:200}"> </span></p>
<p aria-level="1"><b><span data-contrast="none">Immediate Workaround</span></b><span data-ccp-props="{&quot;335559738&quot;:360,&quot;335559739&quot;:200}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Do not run zmpurgeoldmbox (or PurgeMovedMailboxRequest via SOAP) after mailbox migrations if your environment uses external object storage.</span></b><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li><span data-contrast="auto">Disable any automation or scripts that trigger zmpurgeoldmbox as part of post-migration cleanup.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li><span data-contrast="auto">Skipping the purge leaves residual local metadata (MySQL + Lucene) on the source server. This is harmless and can be cleaned up after the patch is applied.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li><span data-contrast="auto">zmmboxmove itself is not affected — mailbox migrations continue to work correctly. Only the post-migration purge step is problematic.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
</ul>
<p aria-level="1"><b><span data-contrast="none">The Fix</span></b><span data-ccp-props="{&quot;335559738&quot;:360,&quot;335559739&quot;:200}"> </span></p>
<p><span data-contrast="auto">The corrected behavior in 10.1.17 will be:</span><span data-ccp-props="{&quot;335559739&quot;:160}"> </span></p>
<table data-tablestyle="MsoNormalTable" data-tablelook="1184" aria-rowcount="4">
<tbody>
<tr aria-rowindex="1">
<td data-celllook="69905"><b><span data-contrast="none">Storage Type</span></b><span data-ccp-props="{}"> </span></td>
<td data-celllook="69905"><b><span data-contrast="none">Without &#8211;forceDeleteBlobs</span></b><span data-ccp-props="{}"> </span></td>
<td data-celllook="69905"><b><span data-contrast="none">With &#8211;forceDeleteBlobs</span></b><span data-ccp-props="{}"> </span></td>
</tr>
<tr aria-rowindex="2">
<td data-celllook="4369"><span data-contrast="none">Internal (local)</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="4369"><span data-contrast="none">Blobs deleted</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="4369"><span data-contrast="none">Blobs deleted</span><span data-ccp-props="{}"> </span></td>
</tr>
<tr aria-rowindex="3">
<td data-celllook="69905"><span data-contrast="none">External (non-unified)</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="69905"><b><span data-contrast="none">Blobs preserved</span></b><span data-ccp-props="{}"> </span></td>
<td data-celllook="69905"><span data-contrast="none">Blobs deleted</span><span data-ccp-props="{}"> </span></td>
</tr>
<tr aria-rowindex="4">
<td data-celllook="4369"><span data-contrast="none">External (unified)</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="4369"><b><span data-contrast="none">Blobs preserved</span></b><span data-ccp-props="{}"> </span></td>
<td data-celllook="4369"><span data-contrast="none">Blobs deleted</span><span data-ccp-props="{}"> </span></td>
</tr>
</tbody>
</table>
<ul>
<li><span data-contrast="auto">External blobs will only be deleted with an explicit &#8211;forceDeleteBlobs flag.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="13" data-aria-level="1"><span data-contrast="auto">Targeted release: ZCS 10.1.17 patch.</span></li>
<li aria-setsize="-1" data-leveltext="•" data-font="" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;•&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="13" data-aria-level="1"><span data-contrast="auto">If you need an early-access build, contact Zimbra Support.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
</ul>
<p aria-level="1"><b><span data-contrast="none">What To Do Next</span></b><span data-ccp-props="{&quot;335559738&quot;:360,&quot;335559739&quot;:200}"> </span></p>
<ol>
<li aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Immediately stop running zmpurgeoldmbox after mailbox migrations in any environment with external storage. Disable related automation.</span></li>
<li aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Audit recent migrations: if zmpurgeoldmbox was already run, verify blob integrity on the destination server using:</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
</ol>
<p><span data-contrast="none">zmprov gmi user@example.com</span><span data-ccp-props="{&quot;335559685&quot;:720,&quot;335559738&quot;:80,&quot;335559739&quot;:40}"> </span></p>
<p><span data-contrast="none">zmblobchk -m &lt;mailboxId&gt; -v &#8211;output-used-blobs start</span><span data-ccp-props="{&quot;335559685&quot;:720,&quot;335559739&quot;:120}"> </span></p>
<p><i><span data-contrast="none">If the output shows “blob not found” errors for external locators (containing @@), those blobs have been deleted.</span></i><span data-ccp-props="{&quot;335559685&quot;:720,&quot;335559739&quot;:120}"> </span></p>
<ol>
<li aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">If data loss has occurred, check if your object storage provider supports versioning or soft-delete, there may be a recovery path.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
<li aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Plan for the 10.1.17 patch: after upgrading, you can safely resume zmpurgeoldmbox and clean up residual metadata from the workaround period.</span><span data-ccp-props="{&quot;335559739&quot;:80}"> </span></li>
</ol>
<p aria-level="1"><b><span data-contrast="none">Questions?</span></b><span data-ccp-props="{&quot;335559738&quot;:360,&quot;335559739&quot;:200}"> </span></p>
<p><span data-contrast="auto">If you have questions, please contact Zimbra Support.</span><span data-ccp-props="{&quot;335559739&quot;:160}"> </span></p>
<hr />
<p><b><span data-contrast="none">Affected versions: </span></b><span data-contrast="none">ZCS 10.1.15 through 10.1.16 (all editions)</span><span data-ccp-props="{&quot;335559739&quot;:40}"> </span></p>
<p><b><span data-contrast="none">Fix version: </span></b><span data-contrast="none">ZCS 10.1.17 (targeted)</span><span data-ccp-props="{&quot;335559739&quot;:40}"> </span></p>
<p><b><span data-contrast="none">Tracking reference: </span></b><span data-contrast="none">ZBUG-5265</span><span data-ccp-props="{&quot;335559739&quot;:40}"> </span></p>
<p><b><span data-contrast="none">Severity: </span></b><span data-contrast="none">Critical — potential data loss</span><span data-ccp-props="{&quot;335559739&quot;:40}"> </span></p>
<p>The post <a href="https://blog.zimbra.com/2026/03/product-advisory-zmpurgeoldmbox-may-delete-external-storage-blobs-after-mailbox-migration/">Product Advisory: zmpurgeoldmbox May Delete External Storage Blobs After Mailbox Migration</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Patch Release Update: Zimbra 10.1.16</title>
		<link>https://blog.zimbra.com/2026/02/patch-release-update-zimbra-10-1-16/</link>
		
		<dc:creator><![CDATA[marilyn lee]]></dc:creator>
		<pubDate>Wed, 04 Feb 2026 10:06:56 +0000</pubDate>
				<category><![CDATA[Product News]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14351</guid>

					<description><![CDATA[<p>We heard you! Enhanced Backup and Restore has been a top request from your customers, and from you. We know how critical this is for your deployments, and we&#8217;re grateful you stayed with us while we delivered on the commitment we made on our product roadmap. Stay tuned — more of those roadmap features are [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2026/02/patch-release-update-zimbra-10-1-16/">Patch Release Update: Zimbra 10.1.16</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>We heard you! </strong>Enhanced Backup and Restore has been a top request from your customers, and from you. We know how critical this is for your deployments, and we&#8217;re grateful you stayed with us while we delivered on the commitment we made on our product roadmap. Stay tuned — more of those roadmap features are coming throughout 2026.</p>
<hr />
<p>In addition, this patch addresses multiple security vulnerabilities and Modern Web App improvements designed to streamline your email management and collaboration.</p>
<h3><strong>Patch Security Severity: </strong><span style="color: #ff0201;">High</span></h3>
<h3><strong>Deployment Risk: </strong><strong><span style="color: #ff0201;">High</span></strong></h3>
<ul>
<li><a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.16">Zimbra 10.1.16 (Release Notes)</a></li>
</ul>
<p>We strongly recommend all admins and users to upgrade to Zimbra 10.1.16 for improved stability and enhanced email compatibility.</p>
<hr />
<div data-hs-cos-general-type="widget" data-hs-cos-type="module">
<h2><strong>What&#8217;s New in 10.1.16</strong></h2>
<div>This release introduces major enhancements to the Backup &amp; Restore module, delivering massive gains in performance and disk usage efficiency. Customers can experience up to 50% faster backup performance and up to 45% reduction in storage consumption, while maintaining full backward compatibility.</div>
<p><span style="text-decoration: underline;"><strong>Backup and Restore Enhancements</strong></span></p>
<ul>
<li><strong>Enhanced deduplication: </strong>Deduplication now applies to data stored on both internal and external (S3) storage, eliminating redundant data. This is enabled by default for new backups.</li>
<li><strong>Improved Compression: </strong>Introduces Zstandard (zstd) compression for deduplicated backups, delivering superior results with lower resource usage.</li>
<li><strong>Optional Cross-Session Deduplication: </strong>Reuse unchanged data across backup runs for even greater efficiency.</li>
<li><strong>Full Backward Compatibility: </strong>All existing backups remain restorable; new and legacy backups coexist seamlessly.</li>
</ul>
<p>For more details on the enhancements, configuration details, and upgrade guidance, see our Backup and Restore section in the <a title="https://info.zimbra.com/e3t/Ctc/ZM+113/c1lM304/VW0sPb5mnnpqW7JJdpN13Zk00VyCbyQ5K5wvTN52hRhR3qgz0W8wLKSR6lZ3n6W1g9l1n8tBL1xW5cHvs362mtcMW4jG6Mz1_SjH4W5-W6Jh50pbNwW5zdq4G1cP0FDW1j7cc1868XmxW2RJpHX6q_0jXW7yF_X_8D8BFsN8dD_HrTRFtMW4N8v4f7MvkrmW5y5yLN3jSB_CW2y73RT4zmz0sVqr1vz8ZnvjBW6xYWcL7QDbDSVZPhWz6Y901hW4sLh3Y2zJf7wW4x7hr-7ZXD9TW66qQQZ3l4yynW5ctpR12r6LbsW1wX_f_65N1lvW7D75Q-6hS75fW7X2hM22l3HPMW5GyvQk3B8g0fW6KVXHL49qTFJW3VV3GV2Y_6zzW2pX1dl4PwSz-VWtPl749JlnqW8_3gBf6wnCBcf3rdbLT04" contenteditable="false" href="https://zimbra.github.io/documentation/zimbra-10/adminguide.html#backup_and_restore" target="_blank" rel="noopener" data-hs-link-id="0" data-hs-link-id-v2="DjrLUF7R">admin guide</a>.</p>
<div data-hs-cos-general-type="widget" data-hs-cos-type="rich_text">
<p><span style="text-decoration: underline;"><strong>Security Fixes</strong></span></p>
<p>This release includes important security enhancements and stability improvements:</p>
<ul>
<li>Restored mail rendering stability while maintaining existing security protections</li>
<li>Resolved XSS vulnerability in Zimbra Webmail and Briefcase file sharing</li>
<li>Fixed authenticated LDAP injection through improved input sanitization</li>
<li>Restored PDF preview functionality in Classic UI with security safeguards</li>
<li>Addressed XXE vulnerability in EWS SOAP endpoint</li>
<li>Strengthened CSRF protection with proper token validation</li>
</ul>
</div>
<div data-hs-cos-general-type="widget" data-hs-cos-type="rich_text">
<p><span style="text-decoration: underline;"><strong>Key Modern Web App Improvements</strong></span></p>
<ul>
<li><strong>Email Translation (Chrome only): </strong>Instantly translate emails into your preferred language with auto-detection and easily switch back to original anytime. Admins can enable/disable via Zimlets at COS or user level.</li>
<li><strong>Smarter Search: </strong>Faster, more intuitive search with improved Advanced Search filters and the ability to combine search options for precise results.</li>
</ul>
<p><strong style="font-size: 16px;"><span style="text-decoration: underline;">Ubuntu 24 Support (Beta)</span></strong></p>
</div>
</div>
<p><span style="font-weight: normal;">Ubuntu 24 Support (Beta) is now available with this release.</span></p>
<p><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a0.png" alt="⚠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <span style="font-weight: bold;">Beta Notice:</span> Beta features are unsupported and intended for lab/testing environments only. Do not deploy on production systems.</p>
<hr />
<h2><strong>Additional Improvements and Fixed Issues</strong></h2>
<div data-hs-cos-general-type="widget" data-hs-cos-type="module"><span style="text-decoration: underline;"><strong>Modern Web App Improvements</strong></span></div>
<div data-hs-cos-general-type="widget" data-hs-cos-type="rich_text">
<ul>
<li><strong>Enhanced Briefcase: </strong>Create new documents directly in Modern Web App and seamlessly open files from Classic Web App with full content integrity.</li>
<li><strong>Visual Navigation Upgrade: </strong>Consistent, recognizable icons across Inbox, Drafts, Sent, Trash, and shared folders for easier mail management.</li>
<li><strong>Custom Tag Colors: </strong>Organize messages visually with customizable tag colors that sync across all devices.</li>
<li><strong>Improved Image Preview:</strong> Pan and zoom on images with smooth click-and-drag functionality across all devices.</li>
<li><strong>Zoom Integration: </strong>Schedule and manage Zoom meetings directly from Zimbra with refreshed, reliable integration.</li>
</ul>
</div>
<p><span style="text-decoration: underline;"><strong>Additional Fixed Issues</strong></span></p>
<ul>
<li>20+ bug fixes across Modern Web App, Classic Web App, ActiveSync, EWS, Chat, and Zimbra Desktop improving stability and user experience.</li>
</ul>
<hr />
<h3>Customer Feedback Portal</h3>
<p>Vote on suggested features, propose your own and stay updated with our product roadmap. Join us at <a href="https://pm.zimbra.com/" rel="noopener">pm.zimbra.com</a>, our dedicated customer portal, for product feedback. Contribute to Zimbra&#8217;s evolution!</p>
<p>The post <a href="https://blog.zimbra.com/2026/02/patch-release-update-zimbra-10-1-16/">Patch Release Update: Zimbra 10.1.16</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Patch Release Update: Zimbra 10.1.15</title>
		<link>https://blog.zimbra.com/2025/11/patch-release-update-zimbra-10-1-15/</link>
		
		<dc:creator><![CDATA[marilyn lee]]></dc:creator>
		<pubDate>Tue, 25 Nov 2025 08:35:28 +0000</pubDate>
				<category><![CDATA[Product News]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14341</guid>

					<description><![CDATA[<p>Patch Security Severity: Low  Deployment Risk: Low We have released Zimbra Version 10.1.15, improving email rendering compatibility while maintaining critical security protections. Zimbra 10.1.15 (Release Notes) We strongly recommend all admins and users to upgrade to Zimbra 10.1.15 for improved stability and enhanced email compatibility. End of Life Notice: 10.0 Zimbra 10.0 will reach End of [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2025/11/patch-release-update-zimbra-10-1-15/">Patch Release Update: Zimbra 10.1.15</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><strong>Patch Security Severity: </strong><strong><span style="color: #339966;">Low </span></strong></h3>
<h3><strong>Deployment Risk: </strong><strong><span style="color: #339966;">Low</span></strong></h3>
<hr />
<p>We have released Zimbra Version 10.1.15, improving email rendering compatibility while maintaining critical security protections.</p>
<ul>
<li><a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.15">Zimbra 10.1.15 (Release Notes)</a></li>
</ul>
<p>We strongly recommend all admins and users to upgrade to Zimbra 10.1.15 for improved stability and enhanced email compatibility.</p>
<hr />
<h2><a href="https://www.zimbra.com/product/product-lifecycle/"><strong>End of Life Notice: 10.0</strong></a></h2>
<p>Zimbra 10.0 will reach End of Life on <strong>December 31, 2025</strong>. Customers using this version are advised to plan their <a href="https://www.zimbra.com/product/product-lifecycle/">upgrade/migration to the 10.1 version</a> (our current supported version) to ensure continued security updates and access to the latest features. For assistance during this transition, our support team is available to address any inquiries.</p>
<hr />
<h3>Customer Feedback Portal</h3>
<p>Vote on suggested features, propose your own and stay updated with our product roadmap. Join us at <a href="https://pm.zimbra.com/" rel="noopener">pm.zimbra.com</a>, our dedicated customer portal, for product feedback. Contribute to Zimbra&#8217;s evolution!</p>
<p>The post <a href="https://blog.zimbra.com/2025/11/patch-release-update-zimbra-10-1-15/">Patch Release Update: Zimbra 10.1.15</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Emergency Patch Release: Zimbra 10.1.14</title>
		<link>https://blog.zimbra.com/2025/11/emergency-patch-release-zimbra-10-1-14/</link>
		
		<dc:creator><![CDATA[marilyn lee]]></dc:creator>
		<pubDate>Wed, 12 Nov 2025 06:01:45 +0000</pubDate>
				<category><![CDATA[Product News]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14331</guid>

					<description><![CDATA[<p>EMERGENCY SECURITY PATCH We have released Zimbra Version 10.1.14 to address a critical issue in Version 10.1.13 that impacts IMAP synchronization across multi-server Zimbra environments, causing incorrect message display and synchronization failures. For complete details and implementation guidance, please refer to our release notes: Zimbra 10.1.14 (Release Notes) Customers on Version 10.1.13 Patch Security Severity: Low [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2025/11/emergency-patch-release-zimbra-10-1-14/">Emergency Patch Release: Zimbra 10.1.14</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong><span style="color: #f15922;">EMERGENCY SECURITY PATCH</span></strong></p>
<p>We have released <strong>Zimbra Version 10.1.14 </strong>to address a critical issue in Version 10.1.13 that impacts IMAP synchronization across multi-server Zimbra environments, causing incorrect message display and synchronization failures.</p>
<p>For complete details and implementation guidance, please refer to our release notes:</p>
<ul>
<li><a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.14" target="_blank" rel="noopener noreferrer">Zimbra 10.1.14 (Release Notes)</a></li>
</ul>
<h3><span style="text-decoration: underline;">Customers on Version 10.1.13</span></h3>
<h4><strong>Patch Security Severity: </strong><strong><span style="color: #339966;">Low</span></strong></h4>
<h4><strong>Deployment Risk: </strong><strong><span style="color: #339966;">Low</span></strong></h4>
<p>We strongly encourage all customers with a high IMAP user base who have upgraded to Version 10.1.13 to upgrade to Zimbra 10.1.14 immediately. Customers on Version 10.1.13 with a low IMAP usage pattern may continue using the current version and wait for the upcoming Version 10.1.15.</p>
<h3><span style="text-decoration: underline;">Customers on Version 10.1.12 or earlier</span></h3>
<h4><strong>Patch Security Severity: </strong><strong><span style="color: #ff0201;">High</span></strong></h4>
<h4><strong>Deployment Risk: </strong><strong><span style="color: #339966;">Low</span></strong></h4>
<p>Customers currently on Patch Version 10.1.12 or earlier are recommended to upgrade directly to Version 10.1.14 for improved stability and fixes.</p>
<p>This new patch version also resolved slowdown issues when switching to the Zimbra user post-upgrade to Version 10.1.13. User switching is now significantly faster and more responsive through optimized license data caching.</p>
<hr />
<h3>End of Life Notice: Zimbra 10.0</h3>
<p>Zimbra 10.0 will reach End of Life on December 31, 2025. Customers using this version are advised to plan their upgrade/migration to the 10.1 version (our current supported version) to ensure continued security updates and access to the latest features. For assistance during this transition, our support team is available to address any inquiries.</p>
<hr />
<h3>Customer Feedback Portal</h3>
<p>Vote on suggested features, propose your own and stay updated with our product roadmap. Join us at <a href="https://pm.zimbra.com/" rel="noopener">pm.zimbra.com</a>, our dedicated customer portal, for product feedback. Contribute to Zimbra&#8217;s evolution!</p>
<p>The post <a href="https://blog.zimbra.com/2025/11/emergency-patch-release-zimbra-10-1-14/">Emergency Patch Release: Zimbra 10.1.14</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Patch Release Update: Zimbra 10.1.13, 10.0.18</title>
		<link>https://blog.zimbra.com/2025/11/patch-release-update-zimbra-10-1-13-10-0-18/</link>
		
		<dc:creator><![CDATA[marilyn lee]]></dc:creator>
		<pubDate>Thu, 06 Nov 2025 08:50:45 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://blog.zimbra.com/?p=14318</guid>

					<description><![CDATA[<p>Patch Security Severity: High Deployment Risk: Medium This patch fixes a stored cross-site scripting (XSS) vulnerability and enhances protection by upgrading AntiSamy to version 1.7.8 and removing the outdated code. It includes critical fixes and user experience improvements for the following editions: Zimbra 10.1.13 (Release Notes) Zimbra 10.0.18 (Release Notes) We recommend all administrators and users [&#8230;]</p>
<p>The post <a href="https://blog.zimbra.com/2025/11/patch-release-update-zimbra-10-1-13-10-0-18/">Patch Release Update: Zimbra 10.1.13, 10.0.18</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><strong>Patch Security Severity: </strong><strong><span style="color: #ff0201;">High</span></strong></h3>
<h3><strong>Deployment Risk: </strong><strong><span style="color: #ff9900;">Medium</span></strong></h3>
<hr />
<p><strong>This patch fixes a stored cross-site scripting (XSS) vulnerability and enhances protection by upgrading AntiSamy to version 1.7.8 and removing the outdated code. It includes critical fixes and user experience improvements for the following editions:</strong></p>
<ul>
<li><a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13">Zimbra 10.1.13 (Release Notes)</a></li>
<li><a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18">Zimbra 10.0.18 (Release Notes)</a></li>
</ul>
<p>We recommend all administrators and users to apply this update to strengthen your system&#8217;s stability and ensures uninterrupted service performance.</p>
<hr />
<div data-hs-cos-general-type="widget" data-hs-cos-type="module">
<div data-hs-cos-general-type="widget" data-hs-cos-type="rich_text">
<h2><strong>What&#8217;s New in 10.1.13</strong></h2>
</div>
</div>
<p><span style="text-decoration: underline;"><strong>Communication &amp; Collaboration</strong></span></p>
<ul>
<li><strong>Ignite: </strong>Smart email search with instant suggestions and LDAP-supported external email warning</li>
<li><strong>Modern Web App: </strong>Improved drag-and-drop, calendar management, tag organization, dumpster functionality, and POP/IMAP settings in Modern UI</li>
<li><strong>Zimbra Connector for Outlook (ZCO): </strong>Outlook 2024 compatibility, better meeting proposals and shared folder handling</li>
<li><strong>ActiveSync &amp; Exchange Web Services (EWS):</strong> Reliable iOS attachments and consistent calendar sync across all devices. Following Microsoft&#8217;s recent announcement extending Legacy EWS support to October 2026 (from the previous October 2025 deadline), Zimbra will maintain EWS compatibility across all currently supported Outlook versions, ensuring uninterrupted service for Outlook clients using this protocol.</li>
<li><strong>Chat and Video: </strong>Chat zimlets and extensions have been updated with the latest improvements. Chat installer zfzi-2.0.1 is now available, and the customization version has been updated to 10.2.1, bringing enhanced performance and bug fixes.</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Modern UI Enhancements</strong></span></p>
<ul>
<li><strong>POP/IMAP Management:</strong> Users can now manage email access settings directly from Modern Webmail, including on mobile.</li>
<li><strong>Copy-Paste Formatting:</strong> Content from Excel, PowerPoint, Word, and web pages now keeps its formatting when pasted into emails.</li>
<li><strong>Meeting Control</strong>: Meeting organizers can now customize cancellation messages and choose to cancel single meetings or entire series. Users now have &#8216;Edit Message&#8217; option to personalize their messages before responding.</li>
<li><strong>Enhanced Recovery:</strong> Restore deleted emails, contacts, appointments, and files directly from Trash.</li>
<li><strong>Quick Distribution List View:</strong> See all members of a distribution list instantly from the message preview without having to switch views.</li>
<li><strong>Improved Tags: </strong>Tags now work consistently across all features with bug fixes.</li>
<li><strong>Drag-and-Drop Uploads:</strong> Easily drag files into Briefcase, just like in Classic UI.</li>
<li><strong>One-Click Recipient Removal:</strong> Remove any recipient (To, Cc, Bcc, or invitee) by clicking the &#8220;X&#8221; next to their name across Mail, Calendar, Briefcase, and Contacts.</li>
<li><strong>Redesigned Tag Management: </strong>Cleaner interface makes creating and organizing tags easier with better visuals and accessibility.</li>
<li><strong>Visual Drop Indicators:</strong> Clear highlighting shows exactly where items will land when dragging and dropping across Mail, Briefcase, and Contacts.</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Security Updates</strong></span></p>
<ul>
<li>Enhanced S3 data management and cleanup for mailbox moves</li>
<li>Strengthened TLS handling per updated RFC standards</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Performance Optimizations</strong></span></p>
<ul>
<li>Faster email thread loading with Smart Conversation Loading</li>
<li>Improved performance for large folders sets in Mail and Briefcase</li>
<li>Optimized Briefcase memory management</li>
</ul>
<hr />
<h2><strong>End of Life Notice: 10.0</strong></h2>
<p>Zimbra 10.0 will reach End of Life on December 31, 2025. Customers using this version are advised to plan their upgrade/migration to the 10.1 version (our current supported version) to ensure continued security updates and access to the latest features. For assistance during this transition, our support team is available to address any inquiries.</p>
<hr />
<h3>Customer Feedback Portal</h3>
<p>Vote on suggested features, propose your own and stay updated with our product roadmap. Join us at <a href="https://pm.zimbra.com/" rel="noopener">pm.zimbra.com</a>, our dedicated customer portal, for product feedback. Contribute to Zimbra&#8217;s evolution!</p>
<p>The post <a href="https://blog.zimbra.com/2025/11/patch-release-update-zimbra-10-1-13-10-0-18/">Patch Release Update: Zimbra 10.1.13, 10.0.18</a> appeared first on <a href="https://blog.zimbra.com">Zimbra : Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
