securityonline.info 7/21/2026, 3:22:06 PM · external

Zimbra fixes SNMP command injection and XSS bugs in 10.1.20

Zimbra fixes SNMP command injection and XSS bugs in 10.1.20
Developing story vulnerability 2 articles tracked
Zimbra patches SNMP command injection and XSS vulnerabilities in 10.1.20
CyberSIXT Evidence Panel
Primary Source blog.zimbra.com

ZIMBRA released Collaboration Suite 10.1.20 on July 20, 2026, addressing critical vulnerabilities, including a high-severity SNMP command injection flaw and multiple XSS bugs. These vulnerabilities pose risks to email and collaboration servers, especially those used by governments and businesses.

The update fixes an SNMP flaw allowing command injection via crafted input and several XSS bugs that can execute scripts through malicious attachment names in the Classic Web Client. Additional fixes include an EWS access-control issue, mailbox delegation flaws, SSRF in Nextcloud integration, and mail-forwarding restriction bypasses.

Currently, there are no reports of active exploitation or public proof-of-concept for these vulnerabilities. On-premises deployments earlier than version 10.1.20 need to be upgraded immediately, especially if SNMP notifications are enabled. Users on older versions are urged to plan for upgrades to mitigate these vulnerabilities.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline