Zimbra patches 9 vulnerabilities: critical SNMP injection, four XSS flaws and a mail forwarding bypass

Zimbra has released version 10.1.20, addressing nine vulnerabilities. Among them is a critical command injection issue in SNMP monitoring when notifications are enabled.
The update also fixes four XSS flaws in the Classic Web Client, affecting attachment names, form fields and attachment rendering.
Separately, Zimbra closed a mail forwarding restrictions bypass (CVE-2026-50055), which could have exposed messages even when policies were in place.
No active exploitation has been reported so far, but in email platforms, XSS issues have repeatedly proved to be a real threat.
Email remains one of the most frequently targeted entry points, which is why updates should not be delayed.
Have you already checked the Zimbra versions in your environment?


Latest comments
No comments yet.