top of page

Zimbra 10.1.20 Patches Critical SNMP Command Injection and Multiple XSS Vulnerabilities

  • Jul 21
  • 2 min read

Key Findings


  • Zimbra Collaboration Suite 10.1.20 patches a critical SNMP command injection vulnerability and multiple XSS bugs in the Classic Web Client

  • The SNMP flaw allows arbitrary command execution on servers when SNMP notifications are enabled

  • Four separate XSS vulnerabilities can be triggered through malicious attachment names and crafted input fields

  • Additional patches address EWS access control issues, mailbox delegation flaws, SSRF in Nextcloud integration, and mail-forwarding bypass

  • No active exploitation or public proof-of-concept code exists for these vulnerabilities

  • Patch deployment carries low risk and is rated High severity by Zimbra


Background


Zimbra powers email and collaboration infrastructure for numerous government agencies and businesses worldwide. Because of this widespread deployment, vulnerabilities in the platform attract serious threat actors. The July 20, 2026 release of version 10.1.20 addresses a temporary mitigation that has been in place since an SNMP flaw was first disclosed on June 26. This permanent fix eliminates the need for workarounds on affected systems.


The SNMP Command Injection Vulnerability


The most critical issue in this patch is a command injection flaw in Zimbra's SNMP monitoring component. When SNMP notifications are enabled, attackers can craft malicious input that executes arbitrary system commands on the server. This grants attackers direct control over vulnerable systems. The flaw has remained exploitable for nearly a month with only temporary mitigation available to administrators.


Cross-Site Scripting Issues in Classic Web Client


Four separate XSS vulnerabilities exist in the Classic Web Client. These flaws can be triggered by stored XSS attacks using malicious attachment filenames and by injecting script into crafted fields that execute when rendered. These vulnerabilities are particularly concerning because XSS bugs in Zimbra's email client have a history of exploitation by threat actors seeking to compromise user sessions and steal data.


Additional Authorization and Access Control Flaws


Beyond XSS and command injection, the patch addresses several authorization bypass issues. These include an EWS access control problem, a mailbox delegation authorization flaw, a server-side request forgery in Nextcloud integration, and a mail-forwarding restriction bypass that allows authenticated users to exfiltrate email despite forwarding restrictions being enabled. Rapid7 researcher Jonah Burgess reported the mail-forwarding bypass.


Exploitation Status and Attribution


Zimbra has not reported any active exploitation of these vulnerabilities. No public proof-of-concept code has emerged. However, Google's Threat Analysis Group previously flagged a separate Classic Web Client bug patched in version 10.1.19, suggesting state-sponsored actors have maintained interest in Zimbra vulnerabilities. No CVE identifiers have been published for the 10.1.20 patches at this time.


Required Actions for Administrators


Organizations running on-premises Zimbra Collaboration Suite deployments before version 10.1.20 must upgrade immediately. Administrators who have enabled SNMP notifications should reapply the SNMP mitigation after upgrading. Customers still running older 10.0.x, 9.0.x, or 8.8.15 versions should plan upgrades as well. Organizations should also audit and restrict Classic Web Client exposure given the concentration of XSS flaws in that component.


Sources


  • https://securityonline.info/zimbra-10-1-20-vulnerabilities/

  • https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html

Recent Posts

See All

Comments


  • Youtube

© 2025 by Explain IT Again. Powered and secured by Wix

bottom of page