Patch released Zimbra Email Platform Zimbra
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
CVE Tools coverage
Zimbra has issued security updates for its email platform to resolve several high-severity vulnerabilities, including a critical command injection flaw in the SNMP monitoring component. The latest patch, Zimbra 10.1.20, also resolves four cross-site scripting (XSS) issues in the Classic Web Client. These flaws could allow attackers to execute malicious scripts or bypass mail forwarding restrictions. While there is no evidence of active exploitation, past XSS vulnerabilities in Zimbra have been targeted by threat actors, underscoring the importance of applying this update promptly.