Find notable cyber news and cases, enriched with sources, timelines, and signals.

Zimbra security patch release for CVE-2026-50055

Security Patch Release
First reported
Last updated
Happening score
H score 14
1 unique sources, 1 articles

Summary

Hide ▲

Zimbra 10.1.20 fixes CVE-2026-50055, a mail forwarding restriction bypass affecting Zimbra accounts with forwarding restrictions. The patch closes a flaw that could let authenticated users exfiltrate email even when forwarding controls are enabled. Zimbra said the issue was not flagged as actively exploited.

Related Happenings

Zimbra SNMP monitoring component command injection

Security Patch Release
H score31 First: 21.07.2026 16:18 Last: 21.07.2026 16:18 Sources 1

How related: Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.

About this happening: Zimbra 10.1.20 patches a command injection flaw in the SNMP monitoring component that could permit command execution when SNMP notifications are enabled. The f...

Zimbra Classic Web Client stored XSS security update

Security Patch Release
H score32 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...

Gravity SMTP security patch release for CVE-2026-4020

Security Patch Release
H score16 First: 20.06.2026 12:56 Last: 20.06.2026 12:56 Sources 1

About this happening: Gravity SMTP released version 2.1.5 to fix CVE-2026-4020, closing a medium-severity information disclosure flaw in the WordPress plugin. The patch addresses a bug...

Exim security patch release for CVE-2026-45185

Security Patch Release
H score21 First: 13.05.2026 23:23 Last: 13.05.2026 23:23 Sources 1

About this happening: Exim released version 4.99.3 to fix CVE-2026-45185, closing a remote-code-execution risk in affected mail servers. The patch applies to Exim versions before 4.99...

Synacor Zimbra CVE-2025-48700 security patch release

Security Patch Release
H score76 First: 24.04.2026 16:35 Last: 24.04.2026 16:35 Sources 1

About this happening: Synacor released security patches for CVE-2025-48700, fixing an XSS flaw in Zimbra Classic UI that could be triggered by a malicious email and expose sensiti...

Timeline

  1. 21.07.2026 16:18 2 articles · 3h ago

    Zimbra 10.1.20 patches SNMP command injection and CVE-2026-50055

    Mitigation Patch Update

    Zimbra released 10.1.20 with fixes for nine security vulnerabilities, including a command injection flaw in the SNMP monitoring component when SNMP notifications are enabled, four cross-site scripting flaws in the Classic Web Client, and CVE-2026-50055, a mail forwarding restriction bypass that could let authenticated users exfiltrate email despite forwarding restrictions being enabled. Rapid7 security researcher Jonah Burgess was credited with discovering and reporting the forwarding-bypass flaw.

    Show sources