Zimbra Collaboration Suite 10.1.20 Patches Critical Unauthenticated SNMP/Swatchdog Command Injection Plus Six Additional CVEs — Threadlinqs Intelligence
As of 2026-07-22, Zimbra Collaboration Suite 10.1.20 Patches Critical Unauthenticated SNMP/Swatchdog Command Injection Plus Six Additional CVEs is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1586 · Severity: CRITICAL · Status: PATCHED · Category: VULNERABILITY
Updated: 2026-07-22 · revalidated 1× · latest source
Zimbra Collaboration Suite (ZCS) 10.1.20, released July 20, 2026, patches a critical unauthenticated OS command injection in the SNMP monitoring/Swatchdog component (exploitable only when SNMP
On July 20, 2026, Zimbra released ZCS 10.1.20 (Daffodil line), a security patch release addressing nine distinct vulnerabilities across the platform, none of which Zimbra has assigned a public CVSS score or confirmed as exploited in the wild.
The most severe issue is an unauthenticated OS command injection vulnerability in the SNMP monitoring component, reachable through the Swatchdog service. Swatchdog is Zimbra's internal service-health watchdog, which can invoke SNMP traps/notifications when it detects a failed service. The vulnerability requires that SNMP notifications be enabled and that the Swatchdog service be running -- a configuration common on ZCS deployments that use SNMP-based monitoring integrations (e.g., Nagios, Zabbix, PRTG). An attacker able to reach the vulnerable code path can send a crafted payload that is passed unsanitized into a shell-executed command, yielding arbitrary OS command execution as the zimbra service user, without authentication. This class of vulnerability directly parallels prior Zimbra SNMP/Swatchdog command-injection issues patched in the 10.1.x line, where crafted values reaching a shell subroutine allowed command injection; Zimbra's official guidance for the earlier variant was to disable SNMP notifications entirely if not required, and to reapply any interim hardening after upgrading.
Four stored cross-site scripting (XSS) vulnerabilities were also fixed in the Classic (Ajax) Web Client. Vectors include malicious attachment filenames that are rendered unescaped in the client UI, crafted message fields (e.g., header/subject content), and crafted attachments whose content is parsed and rendered client-side. Exploitation requires a victim to view a maliciously crafted email/attachment inside the Classic Web Client, enabling script execution in the victim's authenticated webmail session -- a precursor to session/token theft, mailbox takeover, or further internal pivoting. One Classic Web Client stored-XSS issue in the immediately prior release (10.1.19, July 7, 2026) was credited to Google's Threat Analysis Group (TAG), indicating continued targeting interest in Zimbra webmail clients by sophisticated actors who have historically used TAG-reported Zimbra XSS bugs for credential and mailbox-data theft against government and NGO targets.
Three vulnerabilities were assigned CVEs and credited to researcher Jonah Burgess of Rapid7: CVE-2026-50055 (mail forwarding restriction bypass) allows an already-authenticated user to circumvent administrator-enforced restrictions on mail auto-forwarding, enabling covert exfiltration of mailbox content to an external address even when forwarding has been explicitly disabled by policy -- a technique of direct relevance to insider-threat and post-compromise data-exfiltration scenarios. CVE-2026-10631 is an access-control defect in the EWS (Exchange Web Services compatibility) extension, which could allow unauthorized access to EWS-exposed mailbox operations/data outside the intended authorization boundary. CVE-2026-50054 is an authorization flaw in the mailbox delegation feature (used for shared/delegate mailbox access), which could let a delegate or attacker obtain access beyond the scope explicitly granted by the mailbox owner or administrator.
A server-side request forgery (SSRF) vulnerability in the Nextcloud integration (used for Zimbra-to-Nextcloud file-sharing/storage linkage) was credited to Research Industrial Systems Engineering (RISE). SSRF in an integration module typically allows an attacker to coerce the ZCS server into issuing attacker-controlled HTTP requests, which can be leveraged to reach internal-only services, cloud metadata endpoints, or other network-segmented resources not otherwise reachable from the internet.
Zimbra's advisory text states 'information disclosure is limited for security vulnerability fixes,' consistent with the vendor's standard practice of withholding technical exploitation detail until patch adoption is widesp
Weaknesses (CWE)
CWE-78, CWE-79, CWE-863, CWE-284, CWE-918, CWE-77
Target sectors: government administration, education, health, finance, technology, telecoms, managedserviceproviders
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-50055, CVE-2026-10631, CVE-2026-50054, T1190, T1566, T1059, T1203, T1505, T1098, T1068, T1078, T1211, T1562