CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Zimbra Patches Critical SNMP Command Injection and Multiple XSS Flaws

July 21, 2026

Zimbra has released security updates addressing nine vulnerabilities in Zimbra 10.1.20, including a critical command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. The vulnerability can be exploited when SNMP notifications are enabled. Additionally, four cross-site scripting (XSS) vulnerabilities were patched in the Classic Web Client: a stored XSS via malicious attachment filenames, two XSS flaws via crafted fields, and an XSS via crafted attachments. A mail forwarding restriction bypass (CVE-2026-50055) was also fixed, which could allow authenticated users to exfiltrate email despite restrictions. The flaws were reported by Rapid7 researcher Jonah Burgess. While no active exploitation has been reported, Zimbra urges customers to apply updates promptly given past exploitation of XSS bugs in the software.

CVEs: CVE-2026-50055

Companies: Zimbra, Rapid7

Products: Zimbra 10.1.20, Classic Web Client