Zimbra Collaboration versions earlier than 10.1.20 were flagged in security advisories warning of vulnerabilities that require vendor-issued updates. The advisory, identified as AV26-816, prompted national cyber authorities to direct administrators to review Zimbra’s remediation guidance and upgrade affected deployments.
The Canadian Centre for Cyber Security and Guyana National CIRT both urged organizations to assess their exposure, prioritize patching, and apply the available update where necessary. The notices emphasize that systems running unsupported or unpatched Zimbra releases remain at risk until they are brought to 10.1.20 or later in line with the vendor advisory.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On August 14, 2026, the Guyana National CIRT published a notice on the Zimbra advisory and recommended that organizations assess exposure and apply the update where necessary. The notice pointed readers to the vendor advisory for remediation details.
On August 14, 2026, the Canadian Centre for Cyber Security published advisory AV26-816 about the Zimbra vulnerabilities. The notice urged users and administrators to review Zimbra advisories and apply necessary updates as they become available.
On August 13, 2026, Zimbra published a security advisory stating that Zimbra Collaboration versions prior to 10.1.20 are affected by vulnerabilities. The advisory recommended keeping the product updated and applying the relevant update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.