Ravie LakshmananJul 21, 2026Email Security / Vulnerability

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.

As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.

Also patched are four cross-site scripting (XSS) flaws in the Classic Web Client -

A stored cross-site scripting (XSS) vulnerability that could allow malicious attachment filenames to execute script under specific conditions.