Zimbra Collaboration Suite 10.1.20 Patches Critical Unauthenticated SNMP/Swatchdog Command Injection Plus Six Additional CVEs

Zimbra Collaboration Suite 10.1.20 Patches Critical (TL-2026-1586), also tracked as ZCS 10.1.20 Security Patch Release, is a critical-severity software vulnerability, first published 2026-07-21 and last reviewed 2026-07-22. It has no confirmed attribution, affects Zimbra Zimbra Collaboration Suite (ZCS), references 3 CVEs (CVE-2026-50055, CVE-2026-10631, CVE-2026-50054), maps to 22 MITRE ATT&CK techniques (T1005, T1020, T1046), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1586

Threat ID
TL-2026-1586
Also known as
ZCS 10.1.20 Security Patch Release
Severity
CRITICAL
Status
PATCHED
Category
VULNERABILITY
First published
2026-07-21
Last reviewed
2026-07-22
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, education, health, finance, technology, telecoms, managedserviceproviders
Target regions
Global
Detection rules
9
Indicators of compromise
20
Updates
2026-07-22 · revalidated 1× · latest source

Malware and tooling in Zimbra Collaboration Suite 10.1.20 Patches Critical

Malware and tooling: N/A

Zimbra Collaboration Suite (ZCS) 10.1.20, released July 20, 2026, patches a critical unauthenticated OS command injection in the SNMP monitoring/Swatchdog component (exploitable only when SNMP notifications are enabled), four stored XSS flaws in the Classic Web Client, a mail-forwarding restriction bypass (CVE-2026-50055), an EWS extension access-control flaw (CVE-2026-10631), a mailbox delegation authorization flaw (CVE-2026-50054), and an SSRF in the Nextcloud integration. Zimbra reports no known in-the-wild exploitation.

How Zimbra Collaboration Suite 10.1.20 Patches Critical works

On July 20, 2026, Zimbra released ZCS 10.1.20 (Daffodil line), a security patch release addressing nine distinct vulnerabilities across the platform, none of which Zimbra has assigned a public CVSS score or confirmed as exploited in the wild.

The most severe issue is an unauthenticated OS command injection vulnerability in the SNMP monitoring component, reachable through the Swatchdog service. Swatchdog is Zimbra's internal service-health watchdog, which can invoke SNMP traps/notifications when it detects a failed service. The vulnerability requires that SNMP notifications be enabled and that the Swatchdog service be running -- a configuration common on ZCS deployments that use SNMP-based monitoring integrations (e.g., Nagios, Zabbix, PRTG). An attacker able to reach the vulnerable code path can send a crafted payload that is passed unsanitized into a shell-executed command, yielding arbitrary OS command execution as the zimbra service user, without authentication. This class of vulnerability directly parallels prior Zimbra SNMP/Swatchdog command-injection issues patched in the 10.1.x line, where crafted values reaching a shell subroutine allowed command injection; Zimbra's official guidance for the earlier variant was to disable SNMP notifications entirely if not required, and to reapply any interim hardening after upgrading.

Four stored cross-site scripting (XSS) vulnerabilities were also fixed in the Classic (Ajax) Web Client. Vectors include malicious attachment filenames that are rendered unescaped in the client UI, crafted message fields (e.g., header/subject content), and crafted attachments whose content is parsed and rendered client-side. Exploitation requires a victim to view a maliciously crafted email/attachment inside the Classic Web Client, enabling script execution in the victim's authenticated webmail session -- a precursor to session/token theft, mailbox takeover, or further internal pivoting. One Classic Web Client stored-XSS issue in the immediately prior release (10.1.19, July 7, 2026) was credited to Google's Threat Analysis Group (TAG), indicating continued targeting interest in Zimbra webmail clients by sophisticated actors who have historically used TAG-reported Zimbra XSS bugs for credential and mailbox-data theft against government and NGO targets.

Three vulnerabilities were assigned CVEs and credited to researcher Jonah Burgess of Rapid7: CVE-2026-50055 (mail forwarding restriction bypass) allows an already-authenticated user to circumvent administrator-enforced restrictions on mail auto-forwarding, enabling covert exfiltration of mailbox content to an external address even when forwarding has been explicitly disabled by policy -- a technique of direct relevance to insider-threat and post-compromise data-exfiltration scenarios. CVE-2026-10631 is an access-control defect in the EWS (Exchange Web Services compatibility) extension, which could allow unauthorized access to EWS-exposed mailbox operations/data outside the intended authorization boundary. CVE-2026-50054 is an authorization flaw in the mailbox delegation feature (used for shared/delegate mailbox access), which could let a delegate or attacker obtain access beyond the scope explicitly granted by the mailbox owner or administrator.

A server-side request forgery (SSRF) vulnerability in the Nextcloud integration (used for Zimbra-to-Nextcloud file-sharing/storage linkage) was credited to Research Industrial Systems Engineering (RISE). SSRF in an integration module typically allows an attacker to coerce the ZCS server into issuing attacker-controlled HTTP requests, which can be leveraged to reach internal-only services, cloud metadata endpoints, or other network-segmented resources not otherwise reachable from the internet.

Zimbra's advisory text states 'information disclosure is limited for security vulnerability fixes,' consistent with the vendor's standard practice of withholding technical exploitation detail until patch adoption is widespread. No CVSS vectors, no PoC code, and no confirmed in-the-wild exploitation have been published as of the source article date. However, ZCS has a strong recent history of being targeted by both opportunistic and state-nexus actors within weeks of patch disclosure (e.g., CVE-2022-41352, CVE-2022-27924, CVE-2024-45519), so defenders should treat the disclosure-to-exploitation window as short and prioritize patching accordingly.

MITRE ATT&CK techniques used in TL-2026-1586

Collection

T1005 Data from Local System; T1114 Email Collection

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Discovery

T1046 Network Service Discovery; T1087 Account Discovery

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts

Command and Control

T1071 Application Layer Protocol

Persistence

T1098 Account Manipulation; T1505 Server Software Component

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Defense Evasion

T1211 Exploitation for Stealth

Lateral Movement

T1534 Internal Spearphishing

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

Impact

T1565 Data Manipulation

Resource Development

T1583 Acquire Infrastructure

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Zimbra Collaboration Suite 10.1.20 Patches Critical

  • Zimbra — Zimbra Collaboration Suite (ZCS)
    Vulnerable versions: 10.1.19 and earlier 10.1.x; 10.0.x; 9.0.x; 8.8.15
    Fixed in: 10.1.20

Remediation for Zimbra Collaboration Suite 10.1.20 Patches Critical

Patches

  • Upgrade to Zimbra Collaboration Suite 10.1.20 (Daffodil release line), released 2026-07-20

Immediate actions

  • Upgrade all Zimbra Collaboration Suite instances to ZCS 10.1.20 immediately
  • If unable to patch immediately, disable SNMP notifications on the Swatchdog service as an interim mitigation for the command injection flaw
  • Disable the Swatchdog service entirely on internet-facing ZCS nodes if SNMP-based monitoring is not required
  • Audit mail-forwarding rules and delegated mailbox access grants for anomalies predating the patch, since CVE-2026-50055 and CVE-2026-50054 could have been abused by already-authenticated users
  • Restrict/monitor outbound network access from ZCS hosts to reduce SSRF blast radius via the Nextcloud integration

Workarounds

  • Disable SNMP notifications / Swatchdog SNMP integration until upgraded
  • Restrict Classic Web Client attachment preview/rendering where feasible until patched
  • Disable or tightly restrict the Nextcloud integration endpoint until patched

Longer-term hardening

  • Deploy EDR/HIDS on Zimbra mail server hosts to detect anomalous child-process spawning from Java/Zimbra service processes (command injection indicator)
  • Enforce least-privilege network segmentation so ZCS hosts cannot reach internal-only services or cloud metadata endpoints (SSRF containment)
  • Implement periodic review of mailbox delegation and mail-forwarding configurations
  • Subscribe to Zimbra Security Advisories and CISA KEV feeds to track post-disclosure exploitation of this release's CVEs

CVEs associated with Zimbra Collaboration Suite 10.1.20 Patches Critical

CVE-2026-50055, CVE-2026-10631, CVE-2026-50054

Weaknesses (CWE) in Zimbra Collaboration Suite 10.1.20 Patches Critical

CWE-78, CWE-79, CWE-863, CWE-284, CWE-918, CWE-77

Timeline of Zimbra Collaboration Suite 10.1.20 Patches Critical

  • CVE-2022-41352 (Zimbra Amavis/cpio remote code execution) is filed; unknown APT groups are subsequently observed actively exploiting it in the wild, including systematic infection of servers in Central Asia -- established historical precedent for rapid post-disclosure exploitation of Zimbra RCE flaws.
  • Zimbra ships release 9.0.0 P27 addressing CVE-2022-41352; a July 2024 US government bulletin later notes North Korean state-sponsored actors demonstrated interest in this vulnerability.
  • Zimbra patches CVE-2024-45519, a critical OS command injection in the postjournal service, across versions 8.8.15 Patch 46, 9.0.0 Patch 41, 10.0.9, and 10.1.1.
  • ProjectDiscovery publishes a detailed technical write-up and PoC exploit for CVE-2024-45519.
  • Mass exploitation of CVE-2024-45519 begins in the wild, only one day after the public PoC was released and roughly three weeks after the patch shipped -- illustrating the short disclosure-to-exploitation window typical of Zimbra command-injection flaws.
  • CISA adds prior Zimbra Classic Web Client XSS CVE-2025-48700 (CVSS 6.1) to the Known Exploited Vulnerabilities catalog, confirming active exploitation of Zimbra webmail XSS bugs ahead of the 10.1.20 disclosure.
  • Zimbra releases ZCS 10.1.18, an unrelated prior patch release in the same 10.1.x line.
  • Zimbra publishes an initial security advisory disclosing the critical SNMP command-injection vulnerability roughly 3-4 weeks ahead of the 10.1.20 patched build, per Zimbra's own 10.1.20 patch-release blog post.
  • Zimbra releases ZCS 10.1.19, fixing a stored XSS vulnerability in the Classic Web Client credited to Google's Threat Analysis Group (TAG); SecurityWeek's coverage of ZCS 10.1.20 notes this release came roughly two weeks before the 10.1.20 patch.
  • SecurityWeek and third-party advisories cover a critical SNMP/Swatchdog-related code execution issue in the 10.1.x line, rated Severity S1 by regional partners, with guidance to disable SNMP notifications as interim mitigation.
  • Zimbra releases ZCS 10.1.20 (Daffodil line), patching nine security issues including the unauthenticated SNMP/Swatchdog command injection, four Classic Web Client XSS bugs, CVE-2026-50055, CVE-2026-10631, CVE-2026-50054, and the Nextcloud SSRF.
  • CVE-2026-50055, CVE-2026-10631, and CVE-2026-50054 are not present in the CISA Known Exploited Vulnerabilities catalog as of this date, consistent with no confirmed active exploitation.
  • SecurityWeek publishes coverage of the ZCS 10.1.20 patch release, summarizing the fixed vulnerabilities and stating the advisory makes no mention of any of these issues being exploited in the wild.

Update history for TL-2026-1586

Sources cited for Zimbra Collaboration Suite 10.1.20 Patches Critical

Threats related to Zimbra Collaboration Suite 10.1.20 Patches Critical

Detection coverage for TL-2026-1586

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1586 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats