Patch Release Update: Zimbra 10.1.16

We heard you! Enhanced Backup and Restore has been a top request from your customers, and from you. We know how critical this is for your deployments, and we’re grateful you stayed with us while we delivered on the commitment we made on our product roadmap. Stay tuned — more of those roadmap features are coming throughout 2026.


In addition, this patch addresses multiple security vulnerabilities and Modern Web App improvements designed to streamline your email management and collaboration.

Patch Security Severity: High

Deployment Risk: High

We strongly recommend all admins and users to upgrade to Zimbra 10.1.16 for improved stability and enhanced email compatibility.


What’s New in 10.1.16

This release introduces major enhancements to the Backup & Restore module, delivering massive gains in performance and disk usage efficiency. Customers can experience up to 50% faster backup performance and up to 45% reduction in storage consumption, while maintaining full backward compatibility.

Backup and Restore Enhancements

  • Enhanced deduplication: Deduplication now applies to data stored on both internal and external (S3) storage, eliminating redundant data. This is enabled by default for new backups.
  • Improved Compression: Introduces Zstandard (zstd) compression for deduplicated backups, delivering superior results with lower resource usage.
  • Optional Cross-Session Deduplication: Reuse unchanged data across backup runs for even greater efficiency.
  • Full Backward Compatibility: All existing backups remain restorable; new and legacy backups coexist seamlessly.

For more details on the enhancements, configuration details, and upgrade guidance, see our Backup and Restore section in the admin guide.

Security Fixes

This release includes important security enhancements and stability improvements:

  • Restored mail rendering stability while maintaining existing security protections
  • Resolved XSS vulnerability in Zimbra Webmail and Briefcase file sharing
  • Fixed authenticated LDAP injection through improved input sanitization
  • Restored PDF preview functionality in Classic UI with security safeguards
  • Addressed XXE vulnerability in EWS SOAP endpoint
  • Strengthened CSRF protection with proper token validation

Key Modern Web App Improvements

  • Email Translation (Chrome only): Instantly translate emails into your preferred language with auto-detection and easily switch back to original anytime. Admins can enable/disable via Zimlets at COS or user level.
  • Smarter Search: Faster, more intuitive search with improved Advanced Search filters and the ability to combine search options for precise results.

Ubuntu 24 Support (Beta)

Ubuntu 24 Support (Beta) is now available with this release.

⚠️ Beta Notice: Beta features are unsupported and intended for lab/testing environments only. Do not deploy on production systems.


Additional Improvements and Fixed Issues

Modern Web App Improvements
  • Enhanced Briefcase: Create new documents directly in Modern Web App and seamlessly open files from Classic Web App with full content integrity.
  • Visual Navigation Upgrade: Consistent, recognizable icons across Inbox, Drafts, Sent, Trash, and shared folders for easier mail management.
  • Custom Tag Colors: Organize messages visually with customizable tag colors that sync across all devices.
  • Improved Image Preview: Pan and zoom on images with smooth click-and-drag functionality across all devices.
  • Zoom Integration: Schedule and manage Zoom meetings directly from Zimbra with refreshed, reliable integration.

Additional Fixed Issues

  • 20+ bug fixes across Modern Web App, Classic Web App, ActiveSync, EWS, Chat, and Zimbra Desktop improving stability and user experience.

Customer Feedback Portal

Vote on suggested features, propose your own and stay updated with our product roadmap. Join us at pm.zimbra.com, our dedicated customer portal, for product feedback. Contribute to Zimbra’s evolution!

No comments yet.

Leave a Reply

Copyright © 2022 Zimbra, Inc. All rights reserved.

All information contained in this blog is intended for informational purposes only. Synacor, Inc. is not responsible or liable in any manner for the use or misuse of any technical content provided herein. No specific or implied warranty is provided in association with the information or application of the information provided herein, including, but not limited to, use, misuse or distribution of such information by any user. The user assumes any and all risk pertaining to the use or distribution in any form of any subject matter contained in this blog.

Legal Information | Privacy Policy | Do Not Sell My Personal Information | CCPA Disclosures