Zimbra has rolled out updates to address several critical vulnerabilities within its collaboration suite, announced on Monday. These patches include a fix for a significant command injection flaw first identified in late June.
Details of the Command Injection Vulnerability
The identified command injection vulnerability affects the SNMP monitoring component when SNMP notifications are enabled and the Swatchdog service is operational. This flaw allows unauthenticated attackers to send specifically crafted payloads, enabling them to execute arbitrary operating system commands, potentially compromising the email server.
With the release of version 10.1.20 of the Zimbra Collaboration Suite (ZCS), a permanent resolution for this vulnerability has been implemented, enhancing the security of the platform.
Additional Security Flaws Addressed
In addition to the command injection issue, Zimbra’s update addresses four cross-site scripting (XSS) vulnerabilities found in the Classic Web Client interface. These defects, which could lead to unintended script execution, can be exploited through malicious attachment filenames, manipulated fields, and crafted attachments.
The update also rectifies CVE-2026-50055, a flaw that allowed authenticated users to bypass mail forwarding restrictions, potentially leaking emails. Other patched issues include an access control flaw in the EWS extension (CVE-2026-10631), an authorization bug in mailbox delegation (CVE-2026-50054), and a server-side request forgery (SSRF) vulnerability in the Nextcloud integration.
Recommendations and Future Security Measures
Zimbra has not disclosed extensive details regarding these vulnerabilities but strongly recommends users upgrade to ZCS 10.1.20 to mitigate these security risks. The company has not reported any active exploitation of these vulnerabilities in the wild.
This security update follows a previous patch addressing a critical XSS vulnerability in the Classic Web Client, which could have led to code execution upon opening an email. Zimbra’s proactive approach in addressing these vulnerabilities underscores the importance of regular updates to maintain software security.
Users and administrators are urged to implement these updates promptly to safeguard their systems against potential threats.
