securityaffairs.com 7/21/2026, 6:50:47 PM · external

Zimbra patches critical SNMP command injection flaw in v10.1.20

Zimbra patches critical SNMP command injection flaw in v10.1.20
CyberSIXT Evidence Panel
Primary Source wiki.zimbra.com

ZIMBRA has released version 10.1.20, addressing nine security vulnerabilities, including a critical command injection flaw related to SNMP monitoring. This vulnerability allows arbitrary command execution on affected systems with SNMP notifications enabled. Other patched issues include multiple cross-site scripting (XSS) vulnerabilities, a mail forwarding restriction bypass, and flaws in access controls and Nextcloud integration.

Users are advised to update to the latest version to mitigate risks, following a previous update in July 2026, which fixed a severe XSS vulnerability in the Classic Web Client.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline