Zimbra security advisory (AV26-721)
Serial number: AV26-721 Date: July 20, 2026 On July 20, 2026, Zimbra published a security advisory to address vulnerabilities in the following product: Zimbra Collaboration Suite (ZCS) Classic Web Client – versions prior to v10.1.20 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Patch Release Update: Zimbra 10.1.20 Zimbra Patch Release Updates
CSIRTS triage
- What
- Vulnerabilities have been identified in the Classic Web Client.
- Who is affected
- Users and administrators of Zimbra Collaboration Suite Classic Web Client versions prior to v10.1.20.
- Urgency
- Urgency is unclear due to unknown severity.
- Action
- Upgrade to Zimbra version 10.1.20 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Zimbra Collaboration Suite (ZCS) Classic Web Client
Get an email when a new Zimbra Collaboration Suite (ZCS) Classic Web Client advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/zimbra-security-advisory-av26-721
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30