Zimbra released Zimbra Collaboration Suite 10.1.20 to patch multiple critical and high-severity vulnerabilities affecting its email and collaboration platform, including versions of the Classic Web Client prior to 10.1.20. The most serious issue is a critical unauthenticated command injection flaw in the SNMP monitoring component that could allow arbitrary operating system command execution when SNMP notifications are enabled and the integrated Swatchdog service is running. Zimbra and the Canadian Centre for Cyber Security urged administrators and users to review the advisory and apply the update promptly.
The release also fixes four cross-site scripting vulnerabilities in the Classic Web Client, a mail forwarding restriction bypass tracked as CVE-2026-50055, an access control flaw in the EWS extension tracked as CVE-2026-10631, an authorization issue in mailbox delegation tracked as CVE-2026-50054, and a server-side request forgery bug in the Nextcloud integration. Zimbra said customers should update as soon as possible and did not report evidence that the vulnerabilities had been exploited in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Following the advisory, the Canadian Centre for Cyber Security encouraged users and administrators to review Zimbra's notice and apply the necessary updates. The guidance referenced the patch release update to Zimbra 10.1.20.
On 2026-07-20, Zimbra published security advisory AV26-721 and released Zimbra Collaboration Suite 10.1.20 to address multiple vulnerabilities. The update includes fixes for critical and high-severity issues affecting the Classic Web Client and other components.
On 2026-06-26, Zimbra had previously disclosed the critical SNMP command injection vulnerability later fixed in ZCS 10.1.20. At that time, administrators only had a temporary mitigation until the permanent patch became available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesecurityonline.info
Open sourcesecurityweek.com
Open sourcecyberveille.ch
Open sourcemalware.news
Open sourceblog.zimbra.com
Open sourcewiki.zimbra.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.