Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

The Hacker News by The Hacker News
July 21, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananJul 21, 2026Email Security / Vulnerability

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.

As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.

Also patched are four cross-site scripting (XSS) flaws in the Classic Web Client –

  • A stored cross-site scripting (XSS) vulnerability that could allow malicious attachment filenames to execute script under specific conditions.
  • An XSS vulnerability where crafted fields could execute a malicious script under specific conditions.
  • An XSS vulnerability where a crafted field could execute a malicious script when rendered.
  • An XSS vulnerability where crafted attachments could execute a malicious script when rendered.

Separately, fixes have been released for a mail forwarding restriction bypass (CVE-2026-50055) that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled. Rapid7 security researcher Jonah Burgess has been credited with discovering and reporting the flaw.

The company did not share any additional specifics, stating “in line with industry best practices, information disclosure is limited for security vulnerability fixes.”

The release comes a little over a week after Zimbra patched a critical stored XSS flaw in the Classic Web Client that could result in arbitrary code execution.

Although none of the identified vulnerabilities have been flagged as actively exploited, XSS bugs in the email software have been repeatedly exploited by bad actors in the past, making it crucial that customers apply the updates to keep the environment secure.



Source link

The Hacker News

The Hacker News

Next Post
KORE Begins New Chapter as Private Company Backed by Searchlight Capital Partners and Abry Partners

KORE Begins New Chapter as Private Company Backed by Searchlight Capital Partners and Abry Partners

Recommended.

WIC briefs media on Digital Silk Road Development Forum

WIC briefs media on Digital Silk Road Development Forum

July 4, 2025
Wipro Guides Current Quarter IT Services Revenue Down In Face Of Tariffs, Macroeconomic ‘Uncertainties’

Wipro Guides Current Quarter IT Services Revenue Down In Face Of Tariffs, Macroeconomic ‘Uncertainties’

April 16, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Sohu.com to Report Second Quarter 2026 Financial Results on August 10, 2026

Sohu.com to Report Second Quarter 2026 Financial Results on August 10, 2026

July 31, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio