Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
ID: 4131fa8f-7ade-50f9-a79d-1e551f599649
STIX ID: report--4131fa8f-7ade-50f9-a79d-1e551f599649
Feed Name: The Hacker News
Zimbra released security updates for Zimbra 10.1.20 addressing nine vulnerabilities, including a critical command injection in the SNMP monitoring component, multiple stored/reflected XSS issues in the Classic Web Client, and a mail forwarding restriction bypass (CVE-2026-50055). Rapid7 researcher Jonah Burgess is credited for reporting the mail-forwarding bypass; Zimbra limited disclosure of technical details and urges customers to apply the updates, and the vendor reports no indication of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
