2026-07-22 · view entry permalink →
Zimbra Collaboration Suite 10.1.20 — permanent fix for an SNMP command-injection RCE plus four stored-XSS bugs; NCSC-CH and BSI both flag the release
Zimbra shipped Collaboration Suite (ZCS) 10.1.20 on 2026-07-20, fixing nine security issues; NCSC-CH and BSI CERT-Bund both flagged the release on 2026-07-21 (NCSC-CH, 2026-07-21; BSI CERT-Bund, 2026-07-21). The headline flaw is a command-injection vulnerability in Zimbra's SNMP monitoring component, exploitable when SNMP notifications are enabled, that lets an attacker execute arbitrary OS commands on the mail server; Zimbra describes 10.1.20 as the permanent fix for a vulnerability it first disclosed in a 26 June 2026 advisory and has withheld a CVE identifier and technical specifics "in line with industry best practices" pending wider patch adoption (Zimbra, 2026-07-20; The Hacker News, 2026-07-21). Four stored cross-site-scripting bugs in the Classic Web Client round out the un-CVE'd issues: malicious attachment filenames, crafted fields, and rendered attachments can each trigger script execution inside a victim's authenticated webmail session.
Three issues received CVE identifiers, listed in BSI's advisory: CVE-2026-50055, CVE-2026-10631 and CVE-2026-50054 — all three currently RESERVED on NVD/MITRE. The Hacker News maps CVE-2026-50055 to the mail-forwarding restriction bypass (letting an authenticated attacker exfiltrate mail even where forwarding restrictions are enforced) (The Hacker News, 2026-07-21); the other two correspond to the release's EWS-extension access-control and mailbox-delegation authorization fixes described in Zimbra's own advisory, but the cited sources do not state which CVE maps to which issue. The release also fixes an SSRF in Zimbra's Nextcloud integration. This is the second Zimbra security release inside two weeks, following ZCS 10.1.19's 10 July fix for a separate Classic Web Client crafted-email code-execution bug.
A command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. (Permanent fix for the vulnerability disclosed in our security advisory on 26th June 2026)
A mail forwarding restriction bypass that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.