We always suggest that you use the most recent GA version that you possibly can.
It's a lot of customized instances of a serious collection of open-source software packages - OpenLDAP, MySQL, Apache, Tomcat, Jetty(5.0), Postfix, Lucene, Verity, ClamAV, SpamAssassin, DSPAM (though off by default) AMaViS/Amavisd-new, Aspell, James/Sieve, Perdition, NGINX(5.0), etc.
The engineers balance including new versions of the above with security & enhancements in mind.
If there ever are critical exploits in these apps it's announced it in the forums & NE users are contacted accordingly.
For instance-this wasn't zimbra's fault, but perdition had a flaw:
[updated]Perdition IMAP Proxy Remote Exploit Bug -solved in 4.5.10
