CVE Tools

Zimbra Update Patches Critical Vulnerabilities

SecurityWeekBy Ionut Arghire

PatchZimbra Collaboration Suite

Our summary

Zimbra has issued a new security update addressing multiple high-severity vulnerabilities, including a critical command injection flaw disclosed in late June. The bug affects the SNMP monitoring feature when specific services are active, allowing unauthenticated attackers to execute arbitrary system commands. Version 10.1.20 of the Zimbra Collaboration Suite includes a full fix for this issue, along with patches for four cross-site scripting (XSS) vulnerabilities, a mail forwarding bypass, and several other access control and integration-related flaws. While Zimbra warns users to upgrade immediately, it has not confirmed whether any of these issues have been actively exploited.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store