Zimbra Daffodil DoS flaw patched
A remote denial-of-service vulnerability in Zimbra Collaboration 10.1.x has been patched in version 10.1.18.
The French CERT (CERT-FR) has issued an advisory for CVE-2026-49975, a denial-of-service vulnerability affecting Synacor Zimbra Collaboration Daffodil version 10.1.x. The flaw allows an attacker to remotely trigger a denial-of-service condition against vulnerable Zimbra instances.
Zimbra has released version 10.1.18 to address this vulnerability. Organizations running affected versions of Zimbra Collaboration should apply the security patch as outlined in the vendor's June 16, 2026 security bulletin. No active exploitation or additional technical details have been disclosed in this advisory.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0776/
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free