ZIMBRA has released version 10.1.20, addressing nine security vulnerabilities, including a critical command injection flaw related to SNMP monitoring. This vulnerability allows arbitrary command execution on affected systems with SNMP notifications enabled. Other patched issues include multiple cross-site scripting (XSS) vulnerabilities, a mail forwarding restriction bypass, and flaws in access controls and Nextcloud integration.
Users are advised to update to the latest version to mitigate risks, following a previous update in July 2026, which fixed a severe XSS vulnerability in the Classic Web Client.