news.mlab.sh
Back to the feed
vulnerability

Zimbra Update Patches Critical Vulnerabilities

Critical
Summary

Zimbra has released a critical security update to address several vulnerabilities, including a command injection flaw and XSS defects, that could allow attackers to execute commands and steal emails. The update is essential for users to mitigate the risk of exploitation and maintain system security.

Zimbra announced a critical security update on Monday to address multiple vulnerabilities within its Collaboration Suite. The update focuses on mitigating risks associated with command injection and cross-site scripting (XSS) attacks. Specifically, a command injection vulnerability exists within the SNMP monitoring component, potentially allowing an unauthenticated attacker to execute arbitrary OS commands on the email server if SNMP notifications are enabled and the Swatchdog service is running.

Furthermore, the update resolves several XSS defects in the Classic Web Client, exploitable through malicious attachment filenames, crafted fields, and crafted attachments. The update also addresses a mail forwarding restriction bypass (CVE-2026-10631), enabling attackers to exfiltrate emails even with restrictions in place, and a server-side request forgery (SSRF) bug in the Nextcloud integration.

Zimbra has not disclosed further details about these vulnerabilities, but strongly recommends users upgrade to ZCS 10.1.20 immediately. The update follows a previous patch addressing a similar XSS vulnerability in the Classic Web Client.

This update is crucial to prevent potential exploitation of these flaws, which could lead to significant system compromise. The update is a proactive measure to reduce the attack surface and protect against malicious activity.

Read the full article at SecurityWeek