Zimbra Releases/10.1.17 - Zimbra :: Tech Center (original) (raw)

Zimbra Daffodil (v10.1.17) Patch Release

Release Date: May 28, 2026

Security Fixes

Summary CVE-ID CVSS Score
Fixed an authorization bypass in delegated send handling that could allow authenticated users to send emails impersonating other users. TBD TBD
Addressed a stored XSS vulnerability in the Classic UI where malicious email attachments could execute script content when previewed. TBD TBD
Addressed an authenticated LFI vulnerability in the Briefcase document feature via the packages parameter. TBD TBD
Addressed an unauthenticated LFI vulnerability in the Classic UI via one of the input parameter. TBD TBD
Addressed a Cross-Site Request Forgery (CSRF) vulnerability in the EWS endpoint that could allow unauthorized actions on behalf of authenticated users. TBD TBD
Addressed weak RNG for the zimbraDocumentEditingJwtSecret that could allow offline brute-forcing of the JWT signing secret. TBD TBD

What's New

Ubuntu 24 Support (GA)

With this release Ubuntu 24 Support (GA) is available.

Modern Web App

General

Added Collapse All action (available in conversation view only) Added Go to Latest action (available in conversation view only) Introduced Open in New Tab option for quick access Display Total Messages Count in the header Unread Count indicator added

These enhancements improve navigation efficiency and provide better conversation-level context.

Mail

This feature is disabled by default and can be enabled by admins at the COS or account level using the zimlet "zimbra-zimlet-voice-composer". Once enabled, the microphone option becomes available in the email composer, and users can control it from their Mail settings without requiring a refresh

Classic Web App

Fixed Issues

Zimbra Collaboration

Modern Web App

General

Admin Web Console

Zimbra Connector for Outlook

ActiveSync

Auth

SSHA256 Password Hash Authentication Failure On RHEL 9 and Ubuntu 22 systems, {SSHA256} password hashes may be generated incorrectly, causing authentication failures after password changes or migrations. Workaround: Reset affected user passwords to regenerate valid hashes. Note: Passwords created prior to this issue may continue to work; new passwords after the fix are generated correctly.

Calendar

Chat

Mail

Local configs added:

imap_suggested_batch_copy_size: Number of messages to process per batch during IMAP COPY operations. Default value is set to 5
imap_in_progress_response_thread_pool_size: Max threads in pool for sending InProgress response to client when IMAP COPY operation is in progress. Default value is set as 10
imap_in_progress_response_thread_keep_alive: Time in seconds for the thread sending InProgress response to be kept alive before being terminated. Default values is set to 15 seconds.

Backup Restore

Known Issues

Mail

Backup & Restore

Packages

The package lineup for this release is:

zimbra-patch -> 10.1.17.1778766453-2 zimbra-lds-patch -> 10.1.17.1777365774-1 zimbra-mta-patch -> 10.1.17.1777365774-1 zimbra-onlyoffice-patch -> 10.1.17.1777365774-1 zimbra-proxy-patch -> 10.1.17.1778988677-1 zimbra-ldap-patch -> 10.1.17.1777365774-1 zimbra-core-components -> 10.1.6-1zimbra10.0b1 zimbra-ldap-components -> 10.1.3-1zimbra10.0b1 zimbra-mta-components -> 10.1.5-1zimbra8.8b1 zimbra-lmdb -> 2.5.17-1zimbra10.0b2 zimbra-lmdb-lib -> 2.5.17-1zimbra10.0b2 zimbra-openldap-client -> 2.5.17-1zimbra10.0b2 zimbra-openldap-lib -> 2.5.17-1zimbra10.0b2 zimbra-openldap-server -> 2.5.17-1zimbra10.0b2 zimbra-postfix -> 3.6.14-1zimbra8.7b7 zimbra-zco -> 1951.1778166141-1 zimbra-license-daemon -> 1.0.0.1774413397-1 zimbra-common-mbox-conf-attrs -> 10.1.17.1777012766-1 zimbra-common-mbox-conf-msgs -> 10.1.17.1777362963-1 zimbra-common-core-jar -> 10.1.17.1777362963-1 zimbra-mbox-webclient-war -> 10.1.17.1776247073-1 zimbra-mbox-admin-console-war -> 10.1.17.1767695025-1 zimbra-mbox-ews-service -> 10.1.17.1778765350-1 zimbra-license-tools -> 10.1.17.1777004566-1 zimbra-onlyoffice -> 1.0.1771828636-1 zimbra-modern-ui -> 4.49.0.1777305880-1 zimbra-modern-zimlets -> 4.49.0.1777305880-1 zimbra-zimlet-admin-chat -> 2.1.3.1776773674-1 zimbra-zimlet-attachment-missing-alert -> 1.2.1.1776773674-1 zimbra-zimlet-chat -> 13.1.0.1776773674-1 zimbra-zimlet-classic-chat -> 3.1.0.1776773674-1 zimbra-zimlet-classic-set-default-client -> 1.5.1.1776773674-1 zimbra-zimlet-custom-fonts -> 2.3.0.1776773674-1 zimbra-zimlet-deceptive-link-detector -> 2.3.1.1776773674-1 zimbra-zimlet-desktop-auto-update -> 1.3.0.1776773674-1 zimbra-zimlet-disable-screen-capture -> 1.2.1.1776773674-1 zimbra-zimlet-download-email -> 2.4.0.1776773674-1 zimbra-zimlet-email-defanger -> 2.2.0.1776773674-1 zimbra-zimlet-email-reminder -> 1.3.0.1776773674-1 zimbra-zimlet-external-setting-links -> 1.3.1.1776773674-1 zimbra-zimlet-import-export-ics -> 2.4.0.1776773674-1 zimbra-zimlet-mail-translate -> 1.1.0.1776773674-1 zimbra-zimlet-modern-welcometour -> 6.5.0.1776773674-1 zimbra-zimlet-personal-notes -> 1.2.1.1776773674-1 zimbra-zimlet-preventive-ooo -> 2.2.1.1776773674-1 zimbra-zimlet-signature-template -> 1.3.0.1776773674-1 zimbra-zimlet-spy-blocker -> 2.3.0.1776773674-1 zimbra-zimlet-tlp -> 2.3.0.1776773674-1 zimbra-zimlet-voice-composer -> 1.3.0.1778059415-1 zimbra-zimlet-additional-signature-setting -> 10.0.1.1776773674-1 zimbra-zimlet-ads -> 9.5.0.1776773674-1 zimbra-zimlet-calendar-subscription -> 8.1.1.1776773674-1 zimbra-zimlet-classic-unsupportedbrowser -> 4.2.3.1776773674-1 zimbra-zimlet-date -> 10.2.1.1776773674-1 zimbra-zimlet-emptysubject -> 3.4.1.1776773674-1 zimbra-zimlet-install-pwa -> 7.5.0.1776773674-1 zimbra-zimlet-org-chart -> 5.1.0.1776773674-1 zimbra-zimlet-privacy-protector -> 6.2.1.1776773674-1 zimbra-zimlet-secure-mail -> 5.1.0.1776773674-1 zimbra-zimlet-set-default-client -> 11.4.0.1776773674-1 zimbra-zimlet-sideloader -> 10.0.1.1776773674-1 zimbra-zimlet-user-feedback -> 7.6.0.1776773674-1 zimbra-zimlet-user-sessions-management -> 11.0.1.1776773674-1 zimbra-zimlet-web-search -> 5.5.0.1776773674-1 zimbra-zimlet-classic-document-editor -> 2.4.3.1776773674-1 zimbra-zimlet-document-editor -> 14.1.0.1776773674-1

Patch Installation

Please refer to below link to install 10.1.17 (May 28 2026):

Patch Installation

Quick note: Open Source repo

The steps to download, build, and see our code via Github can be found here:https://github.com/Zimbra/zm-build

Jump to: navigation,search