www.securityweek.com 7/21/2026, 8:31:41 AM · external

Zimbra fixes critical command injection, XSS flaws in ZCS 10.1.20

Zimbra fixes critical command injection, XSS flaws in ZCS 10.1.20
CyberSIXT Evidence Panel
Primary Source blog.zimbra.com

ZIMBRA recently released patches for several critical vulnerabilities in its Collaboration Suite (ZCS) version 10.1.20, addressing a command injection issue, multiple cross-site scripting (XSS) flaws, and access control vulnerabilities. These vulnerabilities could allow unauthorized attackers to execute OS commands, bypass email forwarding restrictions, and exploit server-side request forgery bugs. Although Zimbra has not confirmed any active exploitation of these issues, users are urged to update to the latest version immediately.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline