Patch Now! Back-to-Back Synacor Zimbra Updates Fix Two Sets of Critical Vulnerabilities
In July 2026, Zimbra released two security patches for multiple vulnerabilities affecting the Classic Web Client and other components of Zimbra Collaboration Suite (ZCS). Version 10.1.19 addressed a stored cross-site scripting (XSS) flaw that has not been assigned a CVE. Version 10.1.20 fixed a command-injection issue in the SNMP monitoring component, four additional stored XSS issues in the Classic Web Client, and numerous other flaws.
None of the new vulnerabilities are yet reported as actively exploited, and proof-of-concept (PoC) exploits are not publicly available. However, Zimbra has been a hot target for nation-state exploit campaigns in the past. Previous ZCS flaws have appeared 18 times on CISA’s KEV list. Five of those KEV listed CVEs are associated with ransomware attacks. In July 2026, U.S. and allied security agencies warned that the Russian state-backed group LAUNDRY BEAR has been exploiting ZCS vulnerabilities since at least July 2025[1][2].

Most of the security issues described in the 10.1.19 and 10.1.20 updates are not associated with a CVE. However, the pathway to mitigation is clear — users must update to the most recent version of Zimbra Collaboration Suite (ZCS) for protection. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to identify instances missing the 10.1.19 and 10.1.20 patches [1][2]. Users should upgrade to ZCS 10.1.20 as soon as possible.
A Risk Assessment of Zimbra Collaboration Suite Vulnerabilities
For organizations still using the Classic Web Client, the new flaws present significant risk. The 10.1.19 update addresses a stored XSS issue that can be triggered when a user opens a specially crafted email. The vulnerability has not been associated with a published CVE as of July 27th, 2026, but Zimbra has declared it a critical severity issue. Successful exploitation could expose mailbox information, session data, or account settings, potentially enabling account compromise and data theft.
The 10.1.20 patch addresses four additional stored XSS issues in the Classic Web Client, a command-injection vulnerability in the SNMP component, and flaws affecting mail forwarding restrictions, Exchange Web Services (EWS) access controls, mailbox delegation, and the Zimbra integration for Nextcloud.
Details of New Security Issues Impacting ZCS
Technical details for the security issues disclosed in both the ZCS 10.1.19 and 10.1.20 updates are limited. Also, CVEs have not been published for many of the described flaws.
Fixed in ZCS 10.1.19 (Released on July 7th, 2026):
- Classic Web Client stored XSS fixed in 10.1.19 (no CVE assigned): The flaw can be triggered by opening a specially crafted email. Exploitation allows an attacker to execute a malicious script in a user session and potentially expose mailbox information, session data, or account settings.
Fixed in ZCS 10.1.20 (Released on July 20th, 2026):
- SNMP monitoring (no CVE assigned): A command-injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.
- Classic Web Client stored XSS issues (no CVE assigned): Attachment filenames, crafted fields, and attachments can be designed to to trigger XSS on user’s systems when they view a malicious email.
- CVE-2026-50055 (CVE reserved but not published): A mail-forwarding restriction bypass could allow authenticated users to exfiltrate email despite forwarding restrictions being enabled.
- CVE-2026-10631 (CVE reserved but not published): An Exchange Web Services extension access-controls issue can have an undisclosed impact related to access controls.
- CVE-2026-50054 (CVE reserved but not published): A mailbox delegation authorization issue with undisclosed details.
- Nextcloud integration SSRF (no CVE assigned): A Server Side Request Forgery (SSRF) vulnerability in the Nextcloud integration for ZCS.
Mitigation for New Vulnerabilities in Zimbra Collaboration Suite
Users who have deployed the Classic Web Client should upgrade to ZCS v10.1.20 as soon as possible due to the risk of attacker-controlled XSS. The vendor has not described any workarounds. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to uncover instances missing the 10.1.19 and 10.1.20 patches [1][2].
Summary
Zimbra addressed multiple security issues in July 2026, issuing two security patches for ZCS. The updates address flaws in multiple components. The most critical issues are session-level XSS risk in the Classic Web Client. Other high-risk vulnerabilities include configuration-dependent command injection in SNMP monitoring and access-control or authorization weaknesses that can affect email exposure and delegated access. No active exploitation has been reported, although ZCS has been targeted by Advanced Persistent Threat (APT) actors in the past and is reportedly still an active target.
Start Your Free Trial
Most of the security issues described in the 10.1.19 and 10.1.20 updates are not associated with a CVE. However, the pathway to mitigation is clear – users must update to the most recent version of ZCS for protection. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to uncover instances missing the 10.1.19 and 10.1.20 patches [1][2]. Users should upgrade to ZCS 10.1.20 as soon as possible.
Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.
He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.
Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.



