Find notable cyber news and cases, enriched with sources, timelines, and signals.

Zimbra SNMP monitoring component command injection

Security Patch Release
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

Zimbra 10.1.20 patches a command injection flaw in the SNMP monitoring component that could permit command execution when SNMP notifications are enabled. The fix is part of a broader release that addresses nine security vulnerabilities across the product. Zimbra said the identified issues were not flagged as actively exploited.

Related Happenings

Zimbra security patch release for CVE-2026-50055

Security Patch Release
H score14 First: 21.07.2026 16:18 Last: 21.07.2026 16:18 Sources 1

How related: Separately, fixes have been released for a mail forwarding restriction bypass (CVE-2026-50055) that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.

About this happening: Zimbra 10.1.20 fixes CVE-2026-50055, a mail forwarding restriction bypass affecting Zimbra accounts with forwarding restrictions. The patch closes a flaw that coul...

Zimbra Classic Web Client stored XSS security update

Security Patch Release
H score32 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...

APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities

Campaign
H score37 First: 19.03.2026 16:55 Last: 19.03.2026 16:55 Sources 1

About this happening: APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...

Timeline

  1. 21.07.2026 16:18 2 articles · 4h ago

    Zimbra 10.1.20 patches SNMP command injection and four XSS flaws

    Mitigation Patch Update

    Zimbra released Zimbra 10.1.20 with fixes for nine security vulnerabilities, led by a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. The update also addresses four cross-site scripting flaws in the Classic Web Client and CVE-2026-50055, a mail forwarding restriction bypass that could let authenticated users exfiltrate email despite forwarding restrictions being enabled. Zimbra said none of the identified vulnerabilities have been flagged as actively exploited.

    Show sources