logo

Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug

ID: b6472a6a-419f-543d-b39c-7df557aa7601

STIX ID: report--b6472a6a-419f-543d-b39c-7df557aa7601

Feed Name: Security Affairs

Threat Score
65/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Pierluigi Paganini

...
...

Zimbra released version 10.1.20 to fix nine security vulnerabilities, including a critical SNMP monitoring command injection enabling arbitrary command execution on systems with SNMP notifications enabled; the update also patches multiple XSS flaws in the Classic Web Client, a mail-forwarding restriction bypass, EWS and mailbox delegation access-control issues, and an SSRF in Nextcloud integration — administrators are urged to update promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.