All incidents

Zimbra patches SNMP command injection and XSS vulnerabilities in 10.1.20

vulnerabilityopenJul 21, 2026 — Jul 21, 2026
Zimbra fixes SNMP command injection and XSS bugs in 10.1.20

ZIMBRA has released Collaboration Suite 10.1.20, patching a high‑severity SNMP command injection vulnerability and several cross‑site scripting flaws that affect on‑premises email and collaboration servers used by governments and businesses worldwide.

The update, announced on the Zimbra blog here, addresses an SNMP flaw that lets attackers inject arbitrary operating system commands through specially crafted input, as well as multiple XSS bugs in the Classic Web Client that can be triggered by malicious attachment names to execute scripts in a victim’s browser.

In addition to the SNMP and XSS issues, the patch resolves an Exchange Web Services access‑control problem, mailbox delegation weaknesses, a server‑side request forgery issue in the Nextcloud integration and a bypass of mail‑forwarding restrictions; Zimbra has not assigned CVE identifiers to these flaws at this time.

So far there are no reports of active exploitation or public proof‑of‑concept code for any of the vulnerabilities, and no threat actors have been linked to the issues, but the security team warns that internet‑facing installations remain at risk until the update is applied.

Defenders should upgrade all on‑premises Zimbra deployments to version 10.1.20 immediately, review SNMP community strings and restrict SNMP access to trusted networks, and enforce strict validation of attachment filenames in the Classic Web Client to mitigate the XSS vectors.

Administrators are also advised to audit mailbox delegation rules, verify Exchange Web Services permissions, monitor Nextcloud integration logs for unusual outbound requests and ensure mail‑forwarding policies cannot be overridden by malicious filters.

Intelligence briefing updated Jul 21, 2026

Root sourceblog.zimbra.com
Timeline Coverage

Swipe to explore timeline