Key point: Zimbra 10.1.20 patches nine vulnerabilities, including a known SNMP-RCE flaw and four XSS weaknesses in the Classic Web Client that Russian groups have already exploited against Ukrainian infrastructure.
The Zimbra collaboration suite has released version 10.1.20, which fixes nine security vulnerabilities — including critical code execution flaws on the server and multiple XSS weaknesses in the web client.
The update addresses a permanent solution for a critical vulnerability in the SNMP monitoring component announced in June, which enables command injection when notifications are enabled. Additionally, the new version fixes four cross-site scripting (XSS) vulnerabilities in the Classic Web Client that can be triggered by manipulated file names or when rendering attachments.
XSS flaws are critical for CISOs because they execute code in the user’s browser in the context of the application — with the same permissions as the logged-in user. This enables data theft, session cookie hijacking, or persistence. In 2025, CVE-2025-27915 (XSS in calendar import) was already abused against Brazilian military personnel. In March 2025, a Russian group exploited CVE-2025-66376 (stored XSS) in an attack on a Ukrainian infrastructure agency.
Further patches address a bypass of email forwarding restrictions (a common persistence method after account compromise), access control errors in the EWS extension, authorization issues with mailbox delegation, and a server-side request forgery (SSRF) in the Nextcloud integration.
This is already the second update in July — version 10.1.19 from 7 July also patched an unspecified vulnerability in the Classic Web Client that executes code when opening manipulated emails. Synacor (Zimbra’s owner) recommends immediate patching. While there is no zero-day status for these flaws, APT groups such as Fancy Bear (APT28), Cozy Bear (APT29), and Winter Vivern (TA473) have quickly adapted Zimbra exploits in the past.
Source: www.csoonline.com · Published 22 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.