Zimbra Patches Six Security Flaws, Including a Bug That Lets Strangers Run Commands on Your Email Server
The business email platform Zimbra has released a batch of fixes covering a serious command-injection flaw and five other vulnerabilities. No attacks in the wild have been confirmed, but the company is urging every customer to update immediately.

Key points
- Zimbra released version 10.1.20 of its Collaboration Suite on Monday, patching six security vulnerabilities of varying severity.
- The most serious flaw lets an unauthenticated attacker, meaning someone with no login credentials at all, run arbitrary commands on a Zimbra email server.
- CVE-2026-50055 allowed a logged-in user to quietly forward emails out of an organisation even when forwarding rules were supposed to block that.
- Zimbra says none of the six flaws have been exploited in attacks yet, but has released no technical details to help defenders prioritise.
- Organisations running Zimbra should update to version 10.1.20 as soon as possible.
Zimbra Collaboration Suite, a popular platform that companies use to run their own email and calendar systems, shipped a batch of security fixes on Monday. Six vulnerabilities were addressed. One of them is serious enough to give a complete stranger control over the underlying server.
The headline flaw sits in a component called SNMP, which stands for Simple Network Management Protocol, a standard tool that lets administrators monitor the health of a system remotely. When SNMP notifications are switched on and a related background service called Swatchdog is running, an attacker who has no account and no password can send a specially crafted message that tricks the server into executing any operating-system command they choose. In plain terms: a criminal on the internet could tell the server to do almost anything, from copying out stored emails to installing further malicious software.
Zimbra disclosed the flaw in late June. The permanent fix arrived in version 10.1.20.
How did the other five flaws work?
Four of the remaining bugs are cross-site scripting flaws, where a piece of malicious code hidden inside an email attachment or a crafted filename runs inside a victim's browser when they open or preview the message. The fifth, CVE-2026-50055, is a mail-forwarding bypass: a logged-in employee, or someone who had stolen an employee's password, could silently redirect a company's emails to an outside address even if the organisation had locked down that setting as a security policy.
The update also closes an access-control gap in the EWS extension (CVE-2026-10631, where EWS is a programming interface for connecting third-party apps to the mailbox), an authorisation problem in mailbox delegation (CVE-2026-50054, which controls who can read or send email on someone else's behalf), and a server-side request forgery bug in the Nextcloud file-storage integration. Server-side request forgery is a technique where an attacker tricks a server into making internal network requests on their behalf, potentially exposing systems that should never be reachable from outside.
Zimbra has not published technical details for any of the six issues, and the company says it has no evidence that attackers are actively using them. That said, gaps between disclosure and exploitation have narrowed sharply over recent years, so the absence of known attacks today is not a reason to delay patching.
If your organisation runs Zimbra, the practical step is straightforward: update to Zimbra Collaboration Suite 10.1.20. If you receive email through a provider that runs Zimbra on your behalf, check with them that they have applied the update. Keep an eye on any unexpected email-forwarding rules in your account settings, which is a simple check any employee can perform.



