CVE Tools
Back to feed
Patch released Zimbra Collaboration Suite Zimbra

Zimbra Update Patches Critical Vulnerabilities

SecurityWeek·By Ionut Arghire··1 min read
CVE Tools coverage

Zimbra has issued a new security update addressing multiple high-severity vulnerabilities, including a critical command injection flaw disclosed in late June. The bug affects the SNMP monitoring feature when specific services are active, allowing unauthenticated attackers to execute arbitrary system commands. Version 10.1.20 of the Zimbra Collaboration Suite includes a full fix for this issue, along with patches for four cross-site scripting (XSS) vulnerabilities, a mail forwarding bypass, and several other access control and integration-related flaws. While Zimbra warns users to upgrade immediately, it has not confirmed whether any of these issues have been actively exploited.