logo

Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws

ID: 7021791d-d2f8-512b-b53a-dbaaf0d49bc9

STIX ID: report--7021791d-d2f8-512b-b53a-dbaaf0d49bc9

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

Author: Divya

...
...

Zimbra released version 10.1.20 addressing multiple high-severity vulnerabilities — notably a critical command-injection in the SNMP monitoring component when SNMP notifications are enabled, multiple stored/reflected XSS flaws in the Classic Web Client, an SSRF in Nextcloud integration, a mail-forwarding restriction bypass, and EWS/mailbox access-control fixes — and urges administrators to apply the update and review SNMP and web-client exposure immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.