Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN949
_____________________________________________________________________

DATE                : 29/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):Systems running Zimbra Collaboration Suite
                          versions prior to 10.1.21.
  
=====================================================================
https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.21#Security_Fixes
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
_____________________________________________________________________

Zimbra Daffodil (v10.1.21) Patch Release

Release Date: Sept 24, 2026


Security Fixes

Summary
Addressed a stored cross-site scripting (XSS) vulnerability in the
Classic Web Client where crafted sender display names could execute
malicious script when replying to or forwarding messages with headers
excluded.

WebDAV authentication logic has been updated to strictly validate
token usage types. Pre-MFA tokens are now rejected with an HTTP
status, requiring users to fully complete Multi-Factor Authentication
before accessing WebDAV resources.

Addressed a stored cross-site scripting (XSS) vulnerability in the
Classic Web Client where crafted attachment Content-Location headers
could execute malicious script when clicked.

Fixed a security vulnerability in the self-service password recovery
mechanism that could allow an unauthenticated attacker to predict
recovery codes and reset a user's password.

OpenJDK has been upgraded to version 17.0.19 to fix multiple
vulnerabilities.

Updated the NGINX module to align with security standards and improve
compliance.

Addressed a stored cross-site scripting (XSS) vulnerability in the
Modern Web Client that could be triggered through share invitations.

Addressed a stored XSS vulnerability in the Classic Web Client that
could be triggered through share invitations.

Addressed a stored XSS vulnerability in the Classic Web Client that
could be triggered by specially crafted email content

Addressed a stored XSS vulnerability in the Classic Web Client related
to the handling of From addresses in calendar counter-proposals.

Fixed a security issue in the OnlyOffice document editing integration
that could allow unauthorized file writes and remote code execution
under specific conditions.

Fixed a server-side JavaScript injection vulnerability in the
OnlyOffice integration that could allow an authenticated user to
execute commands on the server under specific conditions. 

_____________________________________________________________________

Bug# 	Summary 	CVE-ID 	CVSS Score 	Zimbra Rating
Fix Release or Patch Version 	Reporter

  	Addressed a stored cross-site scripting (XSS) vulnerability
in the Classic Web Client where crafted sender display names could
execute malicious script when replying to or forwarding messages with
headers excluded. 	CVE-2026-66912 	TBD 	- 	10.1.21
CERT.PL

  	WebDAV authentication logic has been updated to strictly
validate token usage types. Pre-MFA tokens are now rejected with an
HTTP status, requiring users to fully complete Multi-Factor
Authentication before accessing WebDAV resources. 	TBD
TBD 	- 	10.1.21 	Redtail Technology

  	Addressed a stored cross-site scripting (XSS) vulnerability
in the Classic Web Client where crafted attachment Content-Location
headers could execute malicious script when clicked.
CVE-2026-66911 	TBD 	- 	10.1.21
Suraj Disoja from trustfoundry.net     CERT.PL

  	Fixed a security vulnerability in the self-service password
recovery mechanism that could allow an unauthenticated attacker to
predict recovery codes and reset a user's password. 	TBD
TBD 	- 	10.1.21 	Hyunwoo Kim   Himanshu Anand

  	OpenJDK has been upgraded to version 17.0.19 to fix multiple
vulnerabilities. 	N/A 	N/A 	- 	10.1.21 
	
  	Updated the NGINX module to align with security standards
and improve compliance. 	TBD 	TBD 	- 	10.1.21
ETES GmbH

  	Addressed a stored cross-site scripting (XSS) vulnerability
in the Modern Web Client that could be triggered through share
invitations. 	TBD    TBD    -    10.1.21   Jonah Burgess (Rapid7)

  	Addressed a stored XSS vulnerability in the Classic Web
Client that could be triggered through share invitations.
TBD 	TBD 	- 	10.1.21 	Jonah Burgess (Rapid7)

  	Addressed a stored XSS vulnerability in the Classic Web
Client that could be triggered by specially crafted email content.
TBD 	TBD 	- 	10.1.21 	OVHCloud Bug Bounty program

  	Addressed a stored XSS vulnerability in the Classic Web Client
related to the handling of From addresses in calendar counter-proposals.
TBD 	TBD 	- 	10.1.21 	Jonah Burgess (Rapid7)

  	Fixed a security issue in the OnlyOffice document editing
integration that could allow unauthorized file writes and remote code
execution under specific conditions. 	TBD 	TBD 	- 	10.1.21
Jonah Burgess (Rapid7)

  	Fixed a server-side JavaScript injection vulnerability in the
OnlyOffice integration that could allow an authenticated user to
execute commands on the server under specific conditions.
TBD 	TBD 	- 	10.1.21 	Vatican City State Governorate -
DIRTLCSSII - SOC


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




