TL;DR
Zimbra released Collaboration Suite 10.1.20 on July 20, 2026. The update fixes several Zimbra vulnerabilities, including a critical SNMP command injection flaw and multiple XSS bugs. Zimbra rates the patch severity as High, with low deployment risk.
Why it matters
Zimbra runs email and collaboration for many governments and businesses. So flaws in its server draw serious attackers. Public-facing mail servers face the highest exposure here. This release delivers a permanent fix for an SNMP flaw first disclosed on June 26, 2026. Admins had only a temporary mitigation until now. According to Zimbra’s patch release update, the fixes address multiple critical issues.
How the attacks work
The patched Zimbra vulnerabilities span several components. The SNMP bug allows command injection when SNMP notifications are enabled. In that case, crafted input can run system commands on the server. Several XSS bugs sit in the Classic Web Client. There, malicious attachment names or crafted fields can run script when rendered. The update further addresses an EWS access-control issue and a mailbox delegation authorization flaw. It also fixes an SSRF flaw in the Nextcloud integration and a mail-forwarding restriction bypass. This report shares no exploit code.
Exploitation status
Zimbra limits technical detail, in line with its disclosure policy. It reports no active exploitation or public proof-of-concept for these fixes. Still, related Zimbra flaws have drawn advanced threats. Google’s Threat Analysis Group reported a separate Classic Web Client bug patched in 10.1.19. That group often tracks state-sponsored and spyware activity, so the attention is notable. No CVE identifiers have been published for the 10.1.20 fixes yet.
Affected versions and patch
On-premises ZCS deployments before 10.1.20 need the update. First, upgrade to 10.1.20 without delay. Next, if you enabled SNMP notifications, reapply the SNMP mitigation after upgrading. Customers on older 10.0.x, 9.0.x, or 8.8.15 lines should plan upgrades too. Finally, review Classic Web Client exposure, since several Zimbra vulnerabilities target it.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.