Critical Zimbra SNMP Flaw Lets Attackers Execute Malicious Commands
Zimbra has released Zimbra Collaboration Suite (ZCS) version 10.1.20, addressing a critical command injection vulnerability in its SNMP monitoring component along with multiple cross-site scripting (X

Zimbra has released Zimbra Collaboration Suite (ZCS) version 10.1.20, addressing a critical command injection vulnerability in its SNMP monitoring component along with multiple cross-site scripting (XSS) flaws affecting the Classic Web Client. The update, announced by Marilyn Lee on July 20, 2026, carries a High security severity rating with a Low deployment risk, and Zimbra […] The post Critical Zimbra SNMP Flaw Lets Attackers Execute Malicious Commands appeared first on Cyber Security News.
Zimbra has released Zimbra Collaboration Suite (ZCS) version 10.1.20, addressing a critical command injection vulnerability in its SNMP monitoring component along with multiple cross-site scripting (XSS) flaws affecting the Classic Web Client. The update, announced by Marilyn Lee on July 20, 2026, carries a High security severity rating with a Low deployment risk, and Zimbra is urging administrators to upgrade immediately. The most significant fix in this release is a permanent patch for the command injection vulnerability in Zimbra’s SNMP monitoring component, which is triggered when SNMP notifications are enabled. Zimbra 10.1.20 Fixes Critical Flaws This flaw was originally disclosed in a security advisory on June 26, 2026, and 10.1.20 delivers the definitive remediation. Command injection vulnerabilities of this nature typically allow attackers to execute arbitrary system-level commands, potentially leading to full server compromise, making this fix a priority for any organization running SNMP-based monitoring on affected ZCS deployments. The release also resolves four distinct XSS vulnerabilities within the Classic Web Client. These include a stored XSS flaw exploitable through malicious attachment filenames under specific conditions. A stored XSS vulnerability triggered by crafted fields executing malicious scripts, a separate XSS issue where a crafted field executes script upon rendering, and another XSS vulnerability involving crafted attachments that execute malicious script when rendered. Zimbra stated the pattern suggests attackers could leverage email content, filenames, or metadata fields to inject and execute client-side scripts, potentially enabling session hijacking, credential theft, or unauthorized actions within a victim’s webmail session. Additional Security Fixes Beyond the headline SNMP and XSS issues, 10.1.20 patches several other notable security gaps: A mail forwarding restriction bypass allowing authenticated users to exfiltrate email even when forwarding restrictions are enforced. An access control issue in the EWS (Exchange Web Services) extension. An authorization flaw affecting mailbox delegation permissions. A server-side request forgery (SSRF) vulnerability tied to the Nextcloud integration. The forwarding bypass and mailbox delegation issues are particularly relevant for insider threat scenarios, where authenticated but malicious users could exfiltrate sensitive communications despite administrative controls meant to prevent exactly that. It fixes a licensing issue where the “Reset to COS Value” function incorrectly zeroed out feature usage counts instead of restoring correct values, and addresses a mail forwarding bug that blocked legitimate admin-initiated redirects when user forwarding restrictions were active under narrow conditions. Given the critical severity of the SNMP command injection flaw and the breadth of XSS issues affecting the Classic Web Client. Organizations running Zimbra Collaboration Suite should prioritize upgrading to version 10.1.20 as soon as possible. Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. The post Critical Zimbra SNMP Flaw Lets Attackers Execute Malicious Commands appeared first on Cyber Security News.
Join the Discussion
Comments coming soon. Follow us on social media for real-time discussions.


