Zimbra Patches Critical Command Injection and Multiple XSS Vulnerabilities
Email collaboration suite provider **Zimbra** has released urgent patches for **Zimbra 10.1.20**, addressing a critical command injection vulnerability in its SNMP monitoring component and multiple cross-site scripting (XSS) flaws. These fixes are crucial for IT security professionals and privacy-conscious users to safeguard their email environments against potential exploitation.
Email collaboration suite provider **Zimbra** has rolled out essential fixes in **Zimbra 10.1.20** to tackle a total of nine security vulnerabilities.
Topping the list of concerns is a critical command injection vulnerability residing within the **Simple Network Management Protocol (SNMP)** monitoring component. This flaw could be exploited when SNMP notifications are enabled, potentially allowing attackers to execute arbitrary commands.
### Multiple XSS Flaws in Classic Web Client
Beyond the SNMP issue, **Zimbra** has also addressed four cross-site scripting (XSS) vulnerabilities specifically impacting its Classic Web Client:
* A stored XSS vulnerability that could enable malicious script execution via crafted attachment filenames under specific conditions.
* An XSS vulnerability where specially crafted fields could execute malicious scripts.
* Another XSS vulnerability allowing malicious script execution when a crafted field is rendered.
* An XSS vulnerability where crafted attachments could execute scripts upon rendering.
### Mail Forwarding Restriction Bypass
Additionally, the update includes a patch for **CVE-2026-50055**, a mail forwarding restriction bypass vulnerability. Discovered and reported by **Rapid7** security researcher **Jonah Burgess**, this flaw could allow authenticated users to exfiltrate emails even when mail forwarding restrictions are active.
**Zimbra** has stated that, in line with industry best practices, specific details regarding these security vulnerability fixes are limited. This release follows closely on the heels of another critical stored XSS flaw in the Classic Web Client patched just over a week prior, which could have led to arbitrary code execution.
While none of the newly identified vulnerabilities are currently reported as actively exploited, the historical context of XSS bugs in **Zimbra** being repeatedly leveraged by malicious actors underscores the urgency for all customers to apply these updates immediately to maintain a secure environment.