Zimbra SNMP monitoring component command injection
Security Patch Release
Summary
Hide ▲
Show ▼
Zimbra 10.1.20 patches a command injection flaw in the SNMP monitoring component that could permit command execution when SNMP notifications are enabled. The fix is part of a broader release that addresses nine security vulnerabilities across the product. Zimbra said the identified issues were not flagged as actively exploited.
Related Happenings
Zimbra security patch release for CVE-2026-50055
Security Patch Release
H score14
First: 21.07.2026 16:18
Last: 21.07.2026 16:18
Sources 1
How related:
Separately, fixes have been released for a mail forwarding restriction bypass (CVE-2026-50055) that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.
About this happening:
Zimbra 10.1.20 fixes CVE-2026-50055, a mail forwarding restriction bypass affecting Zimbra accounts with forwarding restrictions. The patch closes a flaw that coul...
Zimbra security patch release for CVE-2026-50055
Security Patch ReleaseHow related: Separately, fixes have been released for a mail forwarding restriction bypass (CVE-2026-50055) that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.
About this happening: Zimbra 10.1.20 fixes CVE-2026-50055, a mail forwarding restriction bypass affecting Zimbra accounts with forwarding restrictions. The patch closes a flaw that coul...
Zimbra Classic Web Client stored XSS security update
Security Patch Release
H score32
First: 10.07.2026 14:47
Last: 10.07.2026 14:47
Sources 1
About this happening:
Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...
Zimbra Classic Web Client stored XSS security update
Security Patch ReleaseAbout this happening: Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
Campaign
H score37
First: 19.03.2026 16:55
Last: 19.03.2026 16:55
Sources 1
About this happening:
APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
CampaignAbout this happening: APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
Timeline
-
21.07.2026 16:18 2 articles · 4h ago
Zimbra 10.1.20 patches SNMP command injection and four XSS flaws
Mitigation Patch UpdateZimbra released Zimbra 10.1.20 with fixes for nine security vulnerabilities, led by a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. The update also addresses four cross-site scripting flaws in the Classic Web Client and CVE-2026-50055, a mail forwarding restriction bypass that could let authenticated users exfiltrate email despite forwarding restrictions being enabled. Zimbra said none of the identified vulnerabilities have been flagged as actively exploited.
Show sources
- Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities — thehackernews.com — 21.07.2026 16:18
- Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities — thehackernews.com — 21.07.2026 16:18