logo

Critical Zimbra Flaw Lets Attackers Inject Commands Through the SNMP Monitoring Service

ID: 17d5732c-c931-57b3-a251-c6d945bc058a

STIX ID: report--17d5732c-c931-57b3-a251-c6d945bc058a

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Abinaya

...
...

Zimbra released version 10.1.20 to address a critical SNMP-based command injection vulnerability in the Zimbra Collaboration Suite that can allow remote attackers to execute arbitrary commands via malicious SNMP notifications; the update also fixes multiple XSS, an SSRF in Nextcloud integration, authorization issues, and a mail-forwarding bypass, and administrators are urged to upgrade, harden SNMP configurations, and monitor for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.