Overview
- Zimbra released ZCS 10.1.20 on Tuesday to permanently fix a critical SNMP command-injection flaw and to patch eight other vulnerabilities.
- The SNMP bug affects the suite’s monitoring component and can allow unauthenticated attackers to execute arbitrary OS commands if SNMP notifications are turned on and the integrated Swatchdog service is active.
- The update also fixes four Classic Web Client cross-site scripting flaws that can run malicious scripts via crafted attachment filenames, fields, or rendered content and have been abused historically to steal credentials and mailbox data.
- ZCS 10.1.20 addresses additional access-control and integration issues including CVE-2026-50055 for mail-forwarding bypass, an EWS access-control flaw, a mailbox-delegation authorization issue, and an SSRF in Nextcloud integration, with Rapid7 researcher Jonah Burgess credited for reporting the mail-forwarding bypass.
- Zimbra says it has no evidence of active exploitation and urges immediate upgrades while administrators review logs, watch for abnormal account activity, and apply mitigations such as restricting or disabling the Classic UI if they cannot patch right away.