Zimbra issues ZCS 10.1.20 to fix critical bugs

Zimbra released ZCS 10.1.20 to patch a critical SNMP command-injection flaw and several XSS, SSRF and access-control vulnerabilities.

Zimbra released ZCS 10.1.20 on Monday to address several critical vulnerabilities. The update includes a permanent fix for a command-injection bug in the SNMP monitoring component that is exploitable when SNMP notifications are enabled and the integrated Swatchdog service is running. An unauthenticated attacker could send crafted payloads that execute operating-system commands in the background and potentially compromise an email server.

The patch also fixes four cross-site scripting vulnerabilities in the Classic Web Client. Those flaws can be triggered by specially crafted attachment filenames, manipulated message fields or malformed attachments and may allow script execution when a user opens or interacts with a malicious message or attachment.

Additional fixes in ZCS 10.1.20 cover several tracked issues: CVE-2026-50055, a mail-forwarding restriction bypass that could let authenticated users forward or exfiltrate email despite forwarding controls; CVE-2026-10631, an access-control defect in the Exchange Web Services extension; CVE-2026-50054, an authorization issue related to mailbox delegation; and a server-side request forgery vulnerability in the Nextcloud integration. Zimbra did not publish technical details for the access-control, delegation and SSRF issues and reported no known active exploitation at the time of the release.

The release follows a prior patch issued about two weeks earlier that addressed a separate critical XSS bug in the Classic Web Client capable of leading to code execution when opening an email.

Administrators are advised to upgrade to ZCS 10.1.20 as soon as possible. Where immediate upgrades are not possible, temporary mitigations include disabling SNMP notifications or the Swatchdog service, restricting attachment handling and reviewing forwarding rules, mailbox delegation settings and third-party integrations such as Nextcloud for unusual activity.

Zimbra urged customers to apply the update promptly and withheld exploit details to limit risk while deployments are underway.

Articles by this author