{"id":8850,"date":"2026-07-22T20:26:09","date_gmt":"2026-07-22T20:26:09","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8850"},"modified":"2026-07-22T20:26:09","modified_gmt":"2026-07-22T20:26:09","slug":"critical-zimbra-security-update-fixes-9-vulnerabilities","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8850","title":{"rendered":"Critical Zimbra security update fixes 9 vulnerabilities"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Business email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute malicious code on the server or in users\u2019 browsers.<\/p>\n<p class=\"wp-block-paragraph\">Available in commercial and open-source editions, Zimbra Collaboration Suite is a self-hosted Microsoft Exchange alternative that is popular with businesses, government entities, and educational institutions, which has made it a target for attackers in the past.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blog.zimbra.com\/2026\/07\/patch-release-update-zimbra-10-1-20\/\">Version 10.1.20<\/a> released this week includes patches for nine vulnerabilities, including a permanent fix for a critical flaw announced in June in the SNMP monitoring component that could be exploited to inject commands when notifications are enabled.<\/p>\n<p class=\"wp-block-paragraph\">The release also fixes four cross-site scripting (XSS) vulnerabilities in the Classic Web Client that could allow attackers to execute malicious scripts when users view emails in the web interface. For example, one vulnerability can be triggered through specially crafted attachment filenames and another when users render an attachment.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.csoonline.com\/article\/565192\/what-is-xss-cross-site-scripting-attacks-explained.html\">XSS vulnerabilities<\/a> are dangerous because they execute scripts in the user\u2019s browser in the context of the page. That gives rogue code the same privileges as the user, enabling it to perform malicious actions, exfiltrate data, or even leak session cookies.<\/p>\n<p class=\"wp-block-paragraph\">In 2025, an XSS vulnerability in the calendar import feature of the Zimbra Classic Web Client (CVE-2025-27915) <a href=\"https:\/\/www.secpod.com\/learn\/security-research\/zimbra-flaw-exploited-to-attack-brazils-armed-forces-through-ics-attachments\">was exploited in attacks targeting Brazilian military personnel<\/a>. Many other Zimbra vulnerabilities have been exploited over the years, sometimes as zero-days, especially by Russian state-sponsored APT groups, such as Fancy Bear (APT28), Cozy Bear (APT29), and <a href=\"https:\/\/www.csoonline.com\/article\/574913\/apt-group-winter-vivern-exploits-zimbra-webmail-flaw-to-target-government-entities.html\">Winter Vivern (TA473)<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">A recent incident involved <a href=\"https:\/\/www.seqrite.com\/blog\/operation-ghostmail-zimbra-xss-russian-apt-ukraine\/\">a Russian threat group targeting a Ukrainian critical infrastructure agency<\/a> in March using specifically crafted emails that exploited a known Zimbra stored XXS vulnerability (CVE-2025-66376).<\/p>\n<p class=\"wp-block-paragraph\">Another vulnerability fixed in the newly released Zimbra 10.1.20 could allow authenticated attackers to bypass email forwarding restrictions. Adding email forwarding rules to a compromised account is a common way to achieve persistence and continuously exfiltrate emails from a mailbox over an extended period of time, even if the account password is changed.<\/p>\n<p class=\"wp-block-paragraph\">The release also fixes a security issue related to access controls in the EWS extension, an authorization issue in mailbox delegation, and a <a href=\"https:\/\/www.csoonline.com\/article\/571411\/ssrf-attacks-explained-and-how-to-defend-against-them.html\">server-side request forgery (SSRF)<\/a> vulnerability in the Nextcloud integration. Nextcloud is another self-hosted collaboration suite that is popular with government and public institutions that don\u2019t want to rely on public clouds.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s worth noting that this is the second Zimbra security update this month. <a href=\"https:\/\/blog.zimbra.com\/2026\/07\/patch-release-update-zimbra-10-1-19\/\">Version 10.1.19<\/a>, released on July 7, patched another unspecified security issue in the Classic Web Client that could run malicious code when specially crafted emails were opened by users.<\/p>\n<p class=\"wp-block-paragraph\">Zimbra owner Synacor strongly advises customers to upgrade to the latest available version as soon as possible to keep their environments secure. While none of these flaws had zero-day status, hacker groups have a history for quickly adopting known Zimbra exploits.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Business email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute malicious code on the server or in users\u2019 browsers. Available in commercial and open-source editions, Zimbra Collaboration Suite is a self-hosted Microsoft Exchange alternative that is popular with businesses, government entities, and [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8851,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8850","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8850"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8850"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8850\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8851"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}