Skip to content

Mastering Univ Angers Connection and Zimbra Messaging for the 2026 Academic Year

The CAS authentication of the University of Angers relies on a unique username/password pair that grants access to the ENT, Zimbra, Moodle, and...

Étudiante connectée à la messagerie Zimbra de l'Université d'Angers sur son ordinateur portable en bibliothèque universitaire

The CAS authentication of the University of Angers relies on a unique username/password pair that grants access to the ENT, Zimbra, Moodle, and the Microsoft 365 license. For the start of the 2026 academic year, several changes regarding security and account lifecycle deserve special attention, especially after the critical vulnerability referenced CVE-2026-73570 that affected Zimbra servers this summer.

CVE-2026-73570 and consequences on the Zimbra infrastructure at Univ Angers

The CVE-2026-73570 vulnerability allows for remote code execution via Zimbra’s SNMP service. It has been actively exploited on production servers, to the extent that CISA has added it to its list of exploited vulnerabilities. French university servers have been compromised.

The University of Angers has published a dedicated page for the Zimbra security update, confirming the deployment of patches on its infrastructure. Any Zimbra password that has not been changed since the summer of 2026 must be renewed before the first login of the academic year. We recommend checking for the absence of filtering rules or suspicious redirects in your mailbox settings, as this type of backdoor persists after server patching.

The cyber context for the start of the 2026 academic year is tense. The Ministry of National Education itself reported a security incident affecting data held by its services. For students and staff at Angers, the Univ Angers login via the CAS portal remains the only legitimate entry point. We have detailed this topic from the perspective of the initial configuration, notably cap rla 2.2 0 on Diversity and Employment, which addresses the ENT-Zimbra duo in its entirety.

Male student accessing the ENT login portal of the University of Angers from a common room on campus

Account lifecycle for ENT and Zimbra email after deregistration

The student ENT account remains active for the entire duration of administrative registration. After deregistration, access persists until mid-February of the following year, with Zimbra, Moodle, and Microsoft 365 still functional during this grace period.

After this period, the Zimbra mailbox is deleted. The message history disappears permanently. However, the @univ-angers.fr address is retained as a redirect to a personal address provided in the digital portal.

The concrete trap: if the redirect is not set up before the account closure, messages sent to the university address will be lost without notification. For a student finishing their studies in the summer of 2026, the action window closes around February 2027. We recommend configuring this redirect as soon as the diploma is obtained, without waiting for the grace period.

ENT password recovery: the recurring bottleneck

The ENT password recovery procedure relies on an external email address (Gmail, Outlook, or other) distinct from the @etud.univ-angers.fr address. This address must be provided in the digital portal profile before any loss of access.

The classic scenario at each start of the academic year: a student has never provided a recovery address, or it is no longer valid. The online reset fails, and the only option remains a physical visit to the academic office with an ID. During the start of the academic year, the queues make this process particularly lengthy.

Three checks to perform right now:

  • Confirm that the external email address associated with the ENT account is still accessible and not expired
  • Test the password reset procedure from the CAS page to ensure that the recovery link arrives in the external mailbox
  • Update the phone number associated with the account if the university offers a second verification factor

Student desk with laptop displaying Zimbra email, notebook, and university back-to-school materials in Angers

Configure Zimbra in IMAP on an external mail client

The IMAP protocol remains the recommended method for synchronizing Zimbra with a third-party mail client (Thunderbird, Apple Mail, Outlook desktop). The Zimbra webmail works on all recent browsers, but IMAP synchronization offers offline access and local message backup.

The IMAP connection settings are documented in the university’s Zimbra FAQ. The incoming server uses the secure port with SSL/TLS encryption. The outgoing SMTP server follows the same logic. The identifier is the full CAS login, not the email address.

A technical point that public guides often overlook: IMAP configuration on Android or iOS smartphones sometimes requires disabling OAuth authentication if the mail client attempts to use it by default. Zimbra does not use OAuth but a classic password authentication. On the Gmail app for Android, you must select “Other” and not “Exchange” to avoid an authentication error loop.

Managing large attachments and Zimbra mailbox quota

The Zimbra email system at the University of Angers applies strict sending rules on attachment size. To share a large file, using UA Box (the university’s cloud storage service) is the solution provided by the IT department.

UA Box also underwent a security update in 2026, documented on the university’s website in the same communication as the Zimbra patch. Ensure that your UA Box access works before you need it for a file submission or bulk sending.

Some operational rules to remember:

  • Never send an attachment exceeding the limit set by the email system: always use a UA Box sharing link
  • Regularly empty the Zimbra trash, as deleted messages count towards the quota until they are permanently purged
  • Monitor spam messages filtered into the “Junk Mail” folder, which also consume space and may contain false positives

The start of the 2026 academic year at the University of Angers requires heightened vigilance regarding the security of digital accounts. Between the Zimbra vulnerability exploited this summer and the tight deadlines for post-registration configuration, anticipating these settings before the first class remains the most reliable way to avoid administrative blockages during the busy period.

Mastering Univ Angers Connection and Zimbra Messaging for the 2026 Academic Year