Zimbra Security Update – Patch for XSS, XXE & LDAP Injection Vulnerabilities
## Zimbra Version 10.1.16 Release - Security and Feature Enhancements
Zimbra Version 10.1.16 Release - Security and Feature Enhancements
Zimbra has released version 10.1.16 on Tue, Feb 4, 2026, addressing high-severity vulnerabilities, including cross-site scripting (XSS), XML external entity (XXE), and LDAP injection.
XSS in Webmail/Briefcase: Enhanced input validation and encoding have been implemented to prevent session hijacking and data theft.
XXE in EWS SOAP: External entity processing is disabled to mitigate file disclosure, denial-of-service (DoS), and server-side request forgery (SSRF).
LDAP Injection: Query sanitization has been strengthened to prevent privilege escalation and data leaks.
The update also includes improvements to PDF previews in Classic UI and stronger CSRF protection through token validation.
XSS in Webmail/Briefcase: Enhanced input validation and encoding have been implemented to prevent session hijacking and data theft.
Version 10.1.16 introduces several feature enhancements:
Backup & Restore now operates 50% faster, with 45% less storage usage due to Zstandard compression and deduplication for S3/external storage. The Modern Web App includes email translation (Chrome-only), smarter search, custom tag colors, and Zoom integration. Support for Ubuntu 24 beta is available, though it is recommended to avoid using it in production environments.
Over 20 bug fixes have been applied across ActiveSync, EWS, Chat, and Zimbra Desktop to improve stability. Detailed release notes and admin guides are available for review.
Recommendation for Administrators: Due to high deployment risks, it is advised to test the updates in a staging environment before full deployment. Feedback can be shared at pm.zimbra.com.
The release of this patch highlights the importance of timely updates in maintaining cybersecurity. Prompt action is crucial to avoid potential breaches.
Based on reporting by Cyber Security News.
