Zimbra Collaboration Suite 10.1.20 — permanent fix for an SNMP command-injection RCE plus four stored-XSS bugs; NCSC-CH and BSI both flag the release
Zimbra shipped Collaboration Suite (ZCS) 10.1.20 on 2026-07-20, fixing nine security issues; NCSC-CH and BSI CERT-Bund both flagged the release on 2026-07-21 (NCSC-CH, 2026-07-21; BSI CERT-Bund, 2026-07-21). The headline flaw is a command-injection vulnerability in Zimbra's SNMP monitoring component, exploitable when SNMP notifications are enabled, that lets an attacker execute arbitrary OS commands on the mail server; Zimbra describes 10.1.20 as the permanent fix for a vulnerability it first disclosed in a 26 June 2026 advisory and has withheld a CVE identifier and technical specifics "in line with industry best practices" pending wider patch adoption (Zimbra, 2026-07-20; The Hacker News, 2026-07-21). Four stored cross-site-scripting bugs in the Classic Web Client round out the un-CVE'd issues: malicious attachment filenames, crafted fields, and rendered attachments can each trigger script execution inside a victim's authenticated webmail session.
Three issues received CVE identifiers, listed in BSI's advisory: CVE-2026-50055, CVE-2026-10631 and CVE-2026-50054 — all three currently RESERVED on NVD/MITRE. The Hacker News maps CVE-2026-50055 to the mail-forwarding restriction bypass (letting an authenticated attacker exfiltrate mail even where forwarding restrictions are enforced) (The Hacker News, 2026-07-21); the other two correspond to the release's EWS-extension access-control and mailbox-delegation authorization fixes described in Zimbra's own advisory, but the cited sources do not state which CVE maps to which issue. The release also fixes an SSRF in Zimbra's Nextcloud integration. This is the second Zimbra security release inside two weeks, following ZCS 10.1.19's 10 July fix for a separate Classic Web Client crafted-email code-execution bug.
A command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. (Permanent fix for the vulnerability disclosed in our security advisory on 26th June 2026)
A mail forwarding restriction bypass that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.
Defender actions
- Upgrade on-prem Zimbra to ZCS 10.1.20; where SNMP notifications are not operationally required, disable them to remove the command-injection attack surface entirely rather than relying on the still-undisclosed-detail fix.
ATT&CK mapping
3 techniques mapped from the cited reporting · MITRE ATT&CK v19.1
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Execution TA0002
T1059Command and Scripting Interpreter
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Collection TA0009
T1114.003Email Collection: Email Forwarding Rule
Adversaries may setup email forwarding rules to collect sensitive information. Adversaries may abuse email forwarding rules to monitor the activities of a victim, steal information, and further gain intelligence on the victim or the victim’s organization to use as part of further exploits or operations. Furthermore, email forwarding rules can allow adversaries to maintain persistent access to victim's emails even after compromised credentials are reset by administrators. Most email clients allow users to create inbox rules for various email functions, including forwarding to a different recipient. These rules may be created through a local email application, a web interface, or by command-line interface. Messages can be forwarded to internal or external recipients, and there are no restrictions limiting the extent of this rule. Administrators may also create forwarding rules for user accounts with the same considerations and outcomes.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.