🔴 Critical | Source: The Hacker News
Zimbra has released version 10.1.20 patching nine security vulnerabilities, the most severe being a command injection flaw in its SNMP monitoring component that could allow remote code execution when SNMP notifications are enabled. The release also addresses four cross-site scripting (XSS) vulnerabilities. Zimbra is widely used for enterprise email and collaboration, making unpatched instances a high-value target for attackers.
Security Architect’s Take: Prioritise upgrading any internet-facing or internally exposed Zimbra instances to 10.1.20 immediately; if patching is delayed, disable SNMP notifications as a temporary mitigating control and audit Zimbra exposure at your network perimeter.
Original advisory: Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities