securityaffairs.com 7/21/2026, 6:50:47 PM · external

Zimbra patches critical SNMP command injection flaw in v10.1.20

Zimbra patches critical SNMP command injection flaw in v10.1.20
Developing story vulnerability 2 articles tracked
Zimbra releases security update fixing multiple vulnerabilities
CyberSIXT Evidence Panel
Primary Source wiki.zimbra.com

ZIMBRA has released version 10.1.20, addressing nine security vulnerabilities, including a critical command injection flaw related to SNMP monitoring. This vulnerability allows arbitrary command execution on affected systems with SNMP notifications enabled. Other patched issues include multiple cross-site scripting (XSS) vulnerabilities, a mail forwarding restriction bypass, and flaws in access controls and Nextcloud integration.

Users are advised to update to the latest version to mitigate risks, following a previous update in July 2026, which fixed a severe XSS vulnerability in the Classic Web Client.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline