Skip to content

Actualité Sciences

The latest news

Everything you need to know to access Zimbra Univ Angers and manage your email in 2026

The Zimbra messaging system at the University of Angers remains the hub of communication between students, faculty researchers, and administrative staff. Properly managing your account in 2026 requires…

Étudiante connectée à sa messagerie universitaire Zimbra sur un ordinateur portable dans une bibliothèque universitaire moderne
4 min

The Zimbra messaging system at the University of Angers remains the hub of communication between students, researchers, and administrative staff. Properly managing your account in 2026 requires mastering not only authentication but also understanding the implications of the CVE-2026-73570 vulnerability that affected Zimbra servers during the summer.

CVE-2026-73570: Post-Incident Checks on Zimbra Messaging at Univ Angers

The vulnerability CVE-2026-73570 allowed for remote command execution via the SNMP notification component, without prior authentication. CERT Polska issued the alert on August 17, 2026, followed by IT-Connect on August 27 and CSIRT Benin in early September.

For users at the University of Angers, the direct consequence is as follows: even if the administrator has applied the server-side patch, a prior compromise may have exposed the contents of mailboxes. Password reset links, confidential attachments, login information for other services—all of this passes through the messaging system.

We recommend checking three elements in Zimbra after this type of incident:

  • The automatic forwarding rules: an attacker may have added a silent redirect to an external address. Check in Preferences > Message Filters that no unknown rules are active.
  • Active sessions: in Preferences > Security, the list of current connections should match your devices. Any unrecognized session warrants an immediate password change.
  • Reused passwords: if your Zimbra password was also used on other platforms, change them all. The compromise of one webmail exposes every service where the same identifier is reused.

Before attempting to access Zimbra Univ Angers, ensure these checks are completed. A cleaned account is better than quick access to a potentially compromised mailbox.

University IT agent showing the Zimbra messaging management interface on an administrative workstation

Zimbra Login via ENT Angers: Authentication and Password

Access to the Zimbra webmail is through the ENT of the University of Angers. Authentication relies on the username/password pair of the institutional account. If the password is flagged as too old, the ENT blocks access and redirects to the digital counter for renewal.

An expired password does not mean an account is disabled. The mailbox remains active, but the web interface refuses connection until the renewal is completed. The procedure is done from the digital counter, under “My Account”.

Account Lifespan According to Profile

For students, the Zimbra account remains active for a limited period after the end of enrollment, provided they do not re-enroll. For staff, the account remains open as long as their career or contract is ongoing.

It is possible to provide a personal address in the digital counter to maintain a forwarding of received messages to the institutional address after the link with the university ends.

Setting Up a Third-Party Email Client with Zimbra Angers via IMAP

Access via Thunderbird, Outlook, or a mobile client using IMAP requires adherence to the university’s server settings. The IMAP protocol synchronizes folders in real-time, which is preferable to POP3 for multi-device use.

A technical point often overlooked: third-party clients may require a distinct application password separate from the main ENT password. This dedicated password prevents exposure of the main credentials in the configuration of third-party software.

Parameters to Provide

The incoming IMAP server and outgoing SMTP server are documented in the university’s Zimbra FAQ. We observe that most configuration errors stem from three causes:

  • The IMAP or SMTP port incorrectly specified, often confused with the default unencrypted ports.
  • The type of encryption (SSL/TLS) not selected, causing a silent rejection of the connection.
  • The identifier entered as a full address when the server expects only the short login, or vice versa.

If in doubt, the Zimbra webmail remains the most reliable access. It works on recent browsers without additional configuration.

Two students checking their university Zimbra email on a smartphone on campus in autumn

Spam Management and Sending Rules on Univ Angers Messaging

Zimbra includes an anti-spam filter that automatically classifies suspicious emails into the “Junk” folder. This folder is automatically emptied after a period defined by the administration. A legitimate message classified as spam must be manually moved to the inbox to train the filter.

The trash is also emptied automatically, which regularly surprises users who think they have deleted a message by mistake. If the trash appears empty without any action on your part, it is the automatic purge mechanism that has operated.

On the sending side, the university applies strict rules on mailing lists and sending volume. Mass mailings from an @univ-angers.fr address are restricted to avoid blacklisting the domain. To distribute a large attachment, using the university’s file-sharing platform (accessible from the ENT, under “Digital”) remains the recommended method rather than a direct email send.

Keeping an eye on filters, active sessions, and forwarding rules in your Zimbra inbox is no longer an optional precaution—it’s a security routine to integrate every semester.

Everything you need to know to access Zimbra Univ Angers and manage your email in 2026