Zimbra 10.1.20 patches nine vulnerabilities, including a known SNMP-RCE flaw and four XSS weaknesses in the Classic Web Client that Russian groups have already exploited against Ukrainian infrastructure.
Atlassian Bamboo, Bitbucket, Confluence, Crucible, Fisheye and Jira are affected by multiple vulnerabilities enabling code execution and security bypasses.
An actively exploited XSS vulnerability in Exchange OWA is being patched for current versions but remains unfixed for Exchange 2016/2019 without paid Extended Support.