• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

Patch Now! Back-to-Back Synacor Zimbra Updates Fix Two Sets of Critical Vulnerabilities

Blog

In July 2026, Zimbra released two security patches for multiple vulnerabilities affecting the Classic Web Client and other components of Zimbra Collaboration Suite (ZCS). Version 10.1.19 addressed a stored cross-site scripting (XSS) flaw that has not been assigned a CVE. Version 10.1.20 fixed a command-injection issue in the SNMP monitoring component, four additional stored XSS issues in the Classic Web Client, and numerous other flaws.

None of the new vulnerabilities are yet reported as actively exploited, and proof-of-concept (PoC) exploits are not publicly available. However, Zimbra has been a hot target for nation-state exploit campaigns in the past. Previous ZCS flaws have appeared 18 times on CISA’s KEV list. Five of those KEV listed CVEs are associated with ransomware attacks. In July 2026, U.S. and allied security agencies warned that the Russian state-backed group LAUNDRY BEAR has been exploiting ZCS vulnerabilities since at least July 2025[1][2].

Banner graphic for the Zimbra critical patches blog post, reading 'Critical Zimbra Flaws Fixed, Update Now'

Most of the security issues described in the 10.1.19 and 10.1.20 updates are not associated with a CVE. However, the pathway to mitigation is clear — users must update to the most recent version of Zimbra Collaboration Suite (ZCS) for protection. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to identify instances missing the 10.1.19 and 10.1.20 patches [1][2]. Users should upgrade to ZCS 10.1.20 as soon as possible.

A Risk Assessment of Zimbra Collaboration Suite Vulnerabilities

For organizations still using the Classic Web Client, the new flaws present significant risk. The 10.1.19 update addresses a stored XSS issue that can be triggered when a user opens a specially crafted email. The vulnerability has not been associated with a published CVE as of July 27th, 2026, but Zimbra has declared it a critical severity issue. Successful exploitation could expose mailbox information, session data, or account settings, potentially enabling account compromise and data theft.

The 10.1.20 patch addresses four additional stored XSS issues in the Classic Web Client, a command-injection vulnerability in the SNMP component, and flaws affecting mail forwarding restrictions, Exchange Web Services (EWS) access controls, mailbox delegation, and the Zimbra integration for Nextcloud.

Details of New Security Issues Impacting ZCS

Technical details for the security issues disclosed in both the ZCS 10.1.19 and 10.1.20 updates are limited. Also, CVEs have not been published for many of the described flaws.

Fixed in ZCS 10.1.19 (Released on July 7th, 2026):

  • Classic Web Client stored XSS fixed in 10.1.19 (no CVE assigned): The flaw can be triggered by opening a specially crafted email. Exploitation allows an attacker to execute a malicious script in a user session and potentially expose mailbox information, session data, or account settings.

Fixed in ZCS 10.1.20 (Released on July 20th, 2026):

  • SNMP monitoring (no CVE assigned): A command-injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.
  • Classic Web Client stored XSS issues (no CVE assigned): Attachment filenames, crafted fields, and attachments can be designed to to trigger XSS on user’s systems when they view a malicious email.
  • CVE-2026-50055 (CVE reserved but not published): A mail-forwarding restriction bypass could allow authenticated users to exfiltrate email despite forwarding restrictions being enabled.
  • CVE-2026-10631 (CVE reserved but not published): An Exchange Web Services extension access-controls issue can have an undisclosed impact related to access controls.
  • CVE-2026-50054 (CVE reserved but not published): A mailbox delegation authorization issue with undisclosed details.
  • Nextcloud integration SSRF (no CVE assigned): A Server Side Request Forgery (SSRF) vulnerability in the Nextcloud integration for ZCS.

Mitigation for New Vulnerabilities in Zimbra Collaboration Suite

Users who have deployed the Classic Web Client should upgrade to ZCS v10.1.20 as soon as possible due to the risk of attacker-controlled XSS. The vendor has not described any workarounds. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to uncover instances missing the 10.1.19 and 10.1.20 patches [1][2].

Summary

Zimbra addressed multiple security issues in July 2026, issuing two security patches for ZCS. The updates address flaws in multiple components. The most critical issues are session-level XSS risk in the Classic Web Client. Other high-risk vulnerabilities include configuration-dependent command injection in SNMP monitoring and access-control or authorization weaknesses that can affect email exposure and delegated access. No active exploitation has been reported, although ZCS has been targeted by Advanced Persistent Threat (APT) actors in the past and is reportedly still an active target.

Start Your Free Trial

Most of the security issues described in the 10.1.19 and 10.1.20 updates are not associated with a CVE. However, the pathway to mitigation is clear – users must update to the most recent version of ZCS for protection. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to uncover instances missing the 10.1.19 and 10.1.20 patches [1][2]. Users should upgrade to ZCS 10.1.20 as soon as possible.

 

Contact Test Now Buy Here Back to Overview
Joseph Lee
Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

29. July 2026/by Joseph Lee
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-29 14:31:092026-07-29 14:35:52Patch Now! Back-to-Back Synacor Zimbra Updates Fix Two Sets of Critical Vulnerabilities

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: CVE-2026-16232: Check Point SmartConsole Login Process Actively Exploited and More Link to: CVE-2026-16232: Check Point SmartConsole Login Process Actively Exploited and More CVE-2026-16232: Check Point SmartConsole Login Process Actively Exploited and...
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn