The Zimbra messaging system deployed by the Pyrénées-Orientales Department Council (CD66) serves as the daily communication tool for department agents. Accessing emails, managing the calendar, or finding a contact requires mastering a few technical parameters that vary depending on the chosen connection method. This guide compares the different access methods and details the security considerations, a priority topic since the vulnerabilities actively exploited on Zimbra in 2025-2026.
Zimbra CD66 Webmail vs. Desktop Client: Access Methods Comparison
Two main access categories coexist for consulting departmental email: the web client (webmail) and the desktop client (Outlook, Thunderbird, Mail macOS). Each has distinct characteristics in terms of convenience, features, and security.
| Criterion | Zimbra Webmail (browser) | Desktop Client (Outlook, Thunderbird) |
|---|---|---|
| Access | URL provided by the administration, from any browser | Installation required, Zimbra connector sometimes necessary |
| Calendar and Contacts | Integrated into the web interface | Synchronization via CalDAV/CardDAV or dedicated connector |
| Offline Mode | Limited (browser cache) | Reading and writing possible without connection |
| Session Security | Depends on the browser and manual logout | Local session protected by workstation lock |
| Administration | No server configuration required on the user side | IMAP/SMTP settings or connector to configure |
For a department agent connecting from a shared workstation or while traveling, webmail remains the most straightforward method. Simply enter the connection URL, username, and password.
On the other hand, an agent handling a high volume of emails daily benefits from using a desktop client. Offline writing and advanced folder management compensate for the initial setup time.
Before making a choice, it is useful to consult Zimbra CD66 with Info Tech to check the current connection parameters and recommendations specific to the departmental infrastructure.

Zimbra Messaging Security: Recent Vulnerabilities and Precautions for Agents
Email access security is not limited to choosing a good password. Several documented incidents between 2025 and 2026 show that Zimbra has been targeted by attacks directly affecting the authentication layer and user sessions.
Exploited Vulnerabilities on Zimbra in 2025-2026
Analyses published in November 2025, then expanded in August 2026, revealed the exploitation of the vulnerability CVE-2025-66376, an XSS flaw in the Classic interface of Zimbra. This vulnerability allowed an attacker to hijack an active session without the user clicking on a malicious link.
Meanwhile, a documented attack mode in August 2026 showed that an exposed Zimbra server with the optional SNMP module enabled could be compromised without authentication. The fix was included in Zimbra version 10.1.20, released in August 2026.
Security Measures to Apply to Your CD66 Account
A password change does not always suffice to cut off fraudulent access. Zimbra’s “application passcodes,” these codes generated to connect third-party applications, can survive a simple password change. After any suspicion of unauthorized access, verifying and removing unknown passcodes is recommended.
- Check the list of application passcodes in the security settings of your Zimbra account, and remove those you do not recognize
- Prefer the Modern interface of Zimbra over the Classic interface, as the latter has been the direct target of documented XSS vulnerabilities
- Always log out of webmail after each session, especially on a shared workstation or public computer
- Report any unusual activity (messages sent without your intervention, modified folders) to the departmental IT service
These precautions apply to all Zimbra users in a public administration context, where the data exchanged via email can be sensitive.
Mobile Configuration and Synchronization of the Departmental Calendar
Accessing CD66 email from a smartphone or tablet relies on two options: the dedicated Zimbra app (available on iOS and Android) or manual configuration via IMAP/SMTP protocols for email, CalDAV for the calendar, and CardDAV for contacts.
The Zimbra app offers native synchronization of all collaborative functions (email, calendar, contacts, tasks) without manual protocol configuration. The user enters the server URL, username, and password.
Manual configuration via a native mail client (Mail on iOS, Gmail on Android) requires knowledge of the department’s IMAP and SMTP server addresses. These parameters are provided by the CD66 technical service. The advantage of this approach: it allows the use of a single mail client to consolidate multiple email accounts.

Synchronizing the Zimbra Calendar with an External Calendar
The Zimbra calendar of CD66 can be shared to a third-party calendar (Google Calendar, Outlook) via a read-only ICS link. This function is accessible from the web interface, in the properties of the relevant calendar.
For bidirectional synchronization (changes possible from both calendars), the CalDAV protocol is necessary. Not all calendar clients support it equally, which can lead to synchronization discrepancies on recurring events or shared invitations.
Troubleshooting Common Issues on Zimbra CD66
Some access difficulties frequently arise among department agents. Most can be resolved without IT support intervention.
- Login page inaccessible: clear the browser cache, test with another browser, verify that the entered URL matches the one provided by the administration
- Password rejected after a reset: wait a few minutes, as the propagation of the new password on the Zimbra server may take a short delay
- Attachments not opening: check the maximum size allowed by the server and the file format, as some compressed formats may sometimes be blocked by security policy
- Missing calendar notifications on mobile: ensure that CalDAV synchronization is active and that the app has notification permissions on the operating system
The departmental IT service remains the primary contact point for any persistent issues, particularly account lockouts that may result from an intrusion attempt detected by the system.
The Zimbra messaging system of CD66 meets the daily needs of departmental agents, from simple email sending to shared calendar management. Recent vulnerabilities remind us that access security deserves as much attention as user comfort, especially regarding application passcodes and the choice of web interface.



