Zimbra Collaboration Suite 10.1.20 Patches Critical Unauthenticated SNMP/Swatchdog Command Injection Plus Six Additional CVEs
Zimbra Collaboration Suite 10.1.20 Patches Critical (TL-2026-1586), also tracked as ZCS 10.1.20 Security Patch Release, is a critical-severity software vulnerability, first published 2026-07-21 and last reviewed 2026-07-22. It has no confirmed attribution, affects Zimbra Zimbra Collaboration Suite (ZCS), references 3 CVEs (CVE-2026-50055, CVE-2026-10631, CVE-2026-50054), maps to 22 MITRE ATT&CK techniques (T1005, T1020, T1046), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1586
- Threat ID
- TL-2026-1586
- Also known as
- ZCS 10.1.20 Security Patch Release
- Severity
- CRITICAL
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-07-21
- Last reviewed
- 2026-07-22
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, education, health, finance, technology, telecoms, managedserviceproviders
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 20
- Updates
- 2026-07-22 · revalidated 1× · latest source
Malware and tooling in Zimbra Collaboration Suite 10.1.20 Patches Critical
Malware and tooling: N/A
Zimbra Collaboration Suite (ZCS) 10.1.20, released July 20, 2026, patches a critical unauthenticated OS command injection in the SNMP monitoring/Swatchdog component (exploitable only when SNMP notifications are enabled), four stored XSS flaws in the Classic Web Client, a mail-forwarding restriction bypass (CVE-2026-50055), an EWS extension access-control flaw (CVE-2026-10631), a mailbox delegation authorization flaw (CVE-2026-50054), and an SSRF in the Nextcloud integration. Zimbra reports no known in-the-wild exploitation.
How Zimbra Collaboration Suite 10.1.20 Patches Critical works
On July 20, 2026, Zimbra released ZCS 10.1.20 (Daffodil line), a security patch release addressing nine distinct vulnerabilities across the platform, none of which Zimbra has assigned a public CVSS score or confirmed as exploited in the wild.
The most severe issue is an unauthenticated OS command injection vulnerability in the SNMP monitoring component, reachable through the Swatchdog service. Swatchdog is Zimbra's internal service-health watchdog, which can invoke SNMP traps/notifications when it detects a failed service. The vulnerability requires that SNMP notifications be enabled and that the Swatchdog service be running -- a configuration common on ZCS deployments that use SNMP-based monitoring integrations (e.g., Nagios, Zabbix, PRTG). An attacker able to reach the vulnerable code path can send a crafted payload that is passed unsanitized into a shell-executed command, yielding arbitrary OS command execution as the zimbra service user, without authentication. This class of vulnerability directly parallels prior Zimbra SNMP/Swatchdog command-injection issues patched in the 10.1.x line, where crafted values reaching a shell subroutine allowed command injection; Zimbra's official guidance for the earlier variant was to disable SNMP notifications entirely if not required, and to reapply any interim hardening after upgrading.
Four stored cross-site scripting (XSS) vulnerabilities were also fixed in the Classic (Ajax) Web Client. Vectors include malicious attachment filenames that are rendered unescaped in the client UI, crafted message fields (e.g., header/subject content), and crafted attachments whose content is parsed and rendered client-side. Exploitation requires a victim to view a maliciously crafted email/attachment inside the Classic Web Client, enabling script execution in the victim's authenticated webmail session -- a precursor to session/token theft, mailbox takeover, or further internal pivoting. One Classic Web Client stored-XSS issue in the immediately prior release (10.1.19, July 7, 2026) was credited to Google's Threat Analysis Group (TAG), indicating continued targeting interest in Zimbra webmail clients by sophisticated actors who have historically used TAG-reported Zimbra XSS bugs for credential and mailbox-data theft against government and NGO targets.
Three vulnerabilities were assigned CVEs and credited to researcher Jonah Burgess of Rapid7: CVE-2026-50055 (mail forwarding restriction bypass) allows an already-authenticated user to circumvent administrator-enforced restrictions on mail auto-forwarding, enabling covert exfiltration of mailbox content to an external address even when forwarding has been explicitly disabled by policy -- a technique of direct relevance to insider-threat and post-compromise data-exfiltration scenarios. CVE-2026-10631 is an access-control defect in the EWS (Exchange Web Services compatibility) extension, which could allow unauthorized access to EWS-exposed mailbox operations/data outside the intended authorization boundary. CVE-2026-50054 is an authorization flaw in the mailbox delegation feature (used for shared/delegate mailbox access), which could let a delegate or attacker obtain access beyond the scope explicitly granted by the mailbox owner or administrator.
A server-side request forgery (SSRF) vulnerability in the Nextcloud integration (used for Zimbra-to-Nextcloud file-sharing/storage linkage) was credited to Research Industrial Systems Engineering (RISE). SSRF in an integration module typically allows an attacker to coerce the ZCS server into issuing attacker-controlled HTTP requests, which can be leveraged to reach internal-only services, cloud metadata endpoints, or other network-segmented resources not otherwise reachable from the internet.
Zimbra's advisory text states 'information disclosure is limited for security vulnerability fixes,' consistent with the vendor's standard practice of withholding technical exploitation detail until patch adoption is widespread. No CVSS vectors, no PoC code, and no confirmed in-the-wild exploitation have been published as of the source article date. However, ZCS has a strong recent history of being targeted by both opportunistic and state-nexus actors within weeks of patch disclosure (e.g., CVE-2022-41352, CVE-2022-27924, CVE-2024-45519), so defenders should treat the disclosure-to-exploitation window as short and prioritize patching accordingly.
MITRE ATT&CK techniques used in TL-2026-1586
Collection
T1005 Data from Local System; T1114 Email Collection
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Discovery
T1046 Network Service Discovery; T1087 Account Discovery
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts
Command and Control
T1071 Application Layer Protocol
Persistence
T1098 Account Manipulation; T1505 Server Software Component
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
Defense Evasion
T1211 Exploitation for Stealth
Lateral Movement
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials
Impact
Resource Development
defense-impairment
Affected products and versions in Zimbra Collaboration Suite 10.1.20 Patches Critical
- Zimbra — Zimbra Collaboration Suite (ZCS)
Vulnerable versions: 10.1.19 and earlier 10.1.x; 10.0.x; 9.0.x; 8.8.15
Fixed in: 10.1.20
Remediation for Zimbra Collaboration Suite 10.1.20 Patches Critical
Patches
- Upgrade to Zimbra Collaboration Suite 10.1.20 (Daffodil release line), released 2026-07-20
Immediate actions
- Upgrade all Zimbra Collaboration Suite instances to ZCS 10.1.20 immediately
- If unable to patch immediately, disable SNMP notifications on the Swatchdog service as an interim mitigation for the command injection flaw
- Disable the Swatchdog service entirely on internet-facing ZCS nodes if SNMP-based monitoring is not required
- Audit mail-forwarding rules and delegated mailbox access grants for anomalies predating the patch, since CVE-2026-50055 and CVE-2026-50054 could have been abused by already-authenticated users
- Restrict/monitor outbound network access from ZCS hosts to reduce SSRF blast radius via the Nextcloud integration
Workarounds
- Disable SNMP notifications / Swatchdog SNMP integration until upgraded
- Restrict Classic Web Client attachment preview/rendering where feasible until patched
- Disable or tightly restrict the Nextcloud integration endpoint until patched
Longer-term hardening
- Deploy EDR/HIDS on Zimbra mail server hosts to detect anomalous child-process spawning from Java/Zimbra service processes (command injection indicator)
- Enforce least-privilege network segmentation so ZCS hosts cannot reach internal-only services or cloud metadata endpoints (SSRF containment)
- Implement periodic review of mailbox delegation and mail-forwarding configurations
- Subscribe to Zimbra Security Advisories and CISA KEV feeds to track post-disclosure exploitation of this release's CVEs
CVEs associated with Zimbra Collaboration Suite 10.1.20 Patches Critical
CVE-2026-50055, CVE-2026-10631, CVE-2026-50054
Weaknesses (CWE) in Zimbra Collaboration Suite 10.1.20 Patches Critical
CWE-78, CWE-79, CWE-863, CWE-284, CWE-918, CWE-77
Timeline of Zimbra Collaboration Suite 10.1.20 Patches Critical
- CVE-2022-41352 (Zimbra Amavis/cpio remote code execution) is filed; unknown APT groups are subsequently observed actively exploiting it in the wild, including systematic infection of servers in Central Asia -- established historical precedent for rapid post-disclosure exploitation of Zimbra RCE flaws.
- Zimbra ships release 9.0.0 P27 addressing CVE-2022-41352; a July 2024 US government bulletin later notes North Korean state-sponsored actors demonstrated interest in this vulnerability.
- Zimbra patches CVE-2024-45519, a critical OS command injection in the postjournal service, across versions 8.8.15 Patch 46, 9.0.0 Patch 41, 10.0.9, and 10.1.1.
- ProjectDiscovery publishes a detailed technical write-up and PoC exploit for CVE-2024-45519.
- Mass exploitation of CVE-2024-45519 begins in the wild, only one day after the public PoC was released and roughly three weeks after the patch shipped -- illustrating the short disclosure-to-exploitation window typical of Zimbra command-injection flaws.
- CISA adds prior Zimbra Classic Web Client XSS CVE-2025-48700 (CVSS 6.1) to the Known Exploited Vulnerabilities catalog, confirming active exploitation of Zimbra webmail XSS bugs ahead of the 10.1.20 disclosure.
- Zimbra releases ZCS 10.1.18, an unrelated prior patch release in the same 10.1.x line.
- Zimbra publishes an initial security advisory disclosing the critical SNMP command-injection vulnerability roughly 3-4 weeks ahead of the 10.1.20 patched build, per Zimbra's own 10.1.20 patch-release blog post.
- Zimbra releases ZCS 10.1.19, fixing a stored XSS vulnerability in the Classic Web Client credited to Google's Threat Analysis Group (TAG); SecurityWeek's coverage of ZCS 10.1.20 notes this release came roughly two weeks before the 10.1.20 patch.
- SecurityWeek and third-party advisories cover a critical SNMP/Swatchdog-related code execution issue in the 10.1.x line, rated Severity S1 by regional partners, with guidance to disable SNMP notifications as interim mitigation.
- Zimbra releases ZCS 10.1.20 (Daffodil line), patching nine security issues including the unauthenticated SNMP/Swatchdog command injection, four Classic Web Client XSS bugs, CVE-2026-50055, CVE-2026-10631, CVE-2026-50054, and the Nextcloud SSRF.
- CVE-2026-50055, CVE-2026-10631, and CVE-2026-50054 are not present in the CISA Known Exploited Vulnerabilities catalog as of this date, consistent with no confirmed active exploitation.
- SecurityWeek publishes coverage of the ZCS 10.1.20 patch release, summarizing the fixed vulnerabilities and stating the advisory makes no mention of any of these issues being exploited in the wild.
Update history for TL-2026-1586
- 2026-07-22 — Zimbra Patches Critical SNMP Command Injection Vulnerability in Collaboration Suite (CVE-2026-50055, CVE-2026-50054, CVE-2026-10631): What changed No severity/exploitability/status escalation. New report clarifies that two of the nine ZCS 10.1.20 fixes beyond those already tracked were a licensing-feature restoration fix and a mail-forwarding admin-redirect blocking fix,
Sources cited for Zimbra Collaboration Suite 10.1.20 Patches Critical
- Zimbra Update Patches Critical Vulnerabilities
- Zimbra Security Advisories
- Zimbra Releases/10.1.20 Release Notes
- Zimbra Releases/10.1.0 Patch Installation Guide
- Zimbra Patches Critical Code Execution Vulnerability (prior SNMP/Swatchdog advisory)
- Informasi Keamanan: Mengatasi Celah Keamanan SNMP Swatchdog di Zimbra (Severity S1)
- CISA Known Exploited Vulnerabilities Catalog
- Zimbra Security Center
- Unpatched Zimbra RCE bug exploited by attackers (CVE-2022-41352)
- Ongoing exploitation of CVE-2022-41352 (Zimbra 0-day)
- Critical Zimbra RCE vulnerability under mass exploitation (CVE-2024-45519)
- Zimbra CVE-2024-45519 Vulnerability -- Stay Secure by Updating
- CVE-2024-45519 Detail
Threats related to Zimbra Collaboration Suite 10.1.20 Patches Critical
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection
- Zimbra Collaboration Suite Classic Web Client Stored XSS (patched in 10.1.19, no CVE yet)
- Microsoft Exchange Server OWA Cross-Site Scripting Zero-Day CVE-2026-42897 Exploited In the Wild
- ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodology
- Exim Directory Traversal (CVE-2026-66140, CVSS 8.4) and .forward Privilege Escalation (CVE-2026-66141, CVSS 7.4) Enable Local Privilege Escalation via Queue-Name Argument and force_command Abuse
- phpBB Authentication Bypass and OAuth Account Takeover (CVE-2026-48611 / CVE-2026-48612) — Decade-Old Single-Request Login-as-Any-User Flaw, Fixed in 3.3.17
Detection coverage for TL-2026-1586
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1586 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.