Patch Security Severity: High
Deployment Risk: Low
We have released Zimbra Collaboration Suite (ZCS) v10.1.20.
This release contains fixes for multiple critical security issues including a permanent fix for the critical SNMP vulnerability disclosed in our recent security advisory. The release also includes bug fixes in licensing and mail filtering.
We strongly recommend upgrading to this version to keep your environment secure.
Critical Security Fixes
The following issues are fixed in this release:
- A command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. (Permanent fix for the vulnerability disclosed in our security advisory on 26th June 2026)
- A stored cross-site scripting (XSS) vulnerability in the Classic Web Client that could allow malicious attachment filenames to execute script under specific conditions.
- A XSS vulnerability in the Classic Web Client where crafted fields could execute malicious script under specific conditions.
- A XSS vulnerability in the Classic Web Client where a crafted field could execute malicious script when rendered.
- A XSS vulnerability in the Classic Web Client where crafted attachments could execute malicious script when rendered.
- A mail forwarding restriction bypass that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.
- A security issue in the EWS extension related to access controls.
- An authorization issue in mailbox delegation.
- A server-side request forgery (SSRF) vulnerability in the Nextcloud integration.
Note: In line with industry best practices, information disclosure is limited for security vulnerability fixes.
Other Bug Fixes
- Licensing: Corrected “Reset to COS Value” so feature usage counts restore correctly instead of resetting to zero.
- Mail Forwarding: Fixed admin mail redirects being blocked when user forwarding restrictions are switched on under very specific conditions.
If you require assistance applying the new patch or have concerns regarding potential exposure, please raise a support ticket here.

No comments yet.