Patch released Zimbra Collaboration Suite Zimbra
Zimbra Update Patches Critical Vulnerabilities
CVE Tools coverage
Zimbra has issued a new security update addressing multiple high-severity vulnerabilities, including a critical command injection flaw disclosed in late June. The bug affects the SNMP monitoring feature when specific services are active, allowing unauthenticated attackers to execute arbitrary system commands. Version 10.1.20 of the Zimbra Collaboration Suite includes a full fix for this issue, along with patches for four cross-site scripting (XSS) vulnerabilities, a mail forwarding bypass, and several other access control and integration-related flaws. While Zimbra warns users to upgrade immediately, it has not confirmed whether any of these issues have been actively exploited.