logo

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

ID: 4131fa8f-7ade-50f9-a79d-1e551f599649

STIX ID: report--4131fa8f-7ade-50f9-a79d-1e551f599649

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: [email protected] (The Hacker News)

...
...

Zimbra released security updates for Zimbra 10.1.20 addressing nine vulnerabilities, including a critical command injection in the SNMP monitoring component, multiple stored/reflected XSS issues in the Classic Web Client, and a mail forwarding restriction bypass (CVE-2026-50055). Rapid7 researcher Jonah Burgess is credited for reporting the mail-forwarding bypass; Zimbra limited disclosure of technical details and urges customers to apply the updates, and the vendor reports no indication of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.