Zimbra has released critical security patches for its Collaboration Suite, addressing a severe command injection vulnerability and several other flaws that could allow unauthorized server access and data exfiltration.
Key Points
- Zimbra Collaboration Suite version 10.1.20 fixes a critical command injection bug in the SNMP monitoring component.
- The update resolves four cross-site scripting (XSS) vulnerabilities found within the Classic Web Client interface.
- Patches address a mail forwarding restriction bypass, an EWS extension access control issue, and a mailbox delegation authorization flaw.
- A server-side request forgery (SSRF) vulnerability within the Nextcloud integration has been remediated.
- Users are urged to update immediately, though Zimbra has not reported any active exploitation of these vulnerabilities in the wild.