Zimbra is rolling out an update that patches several critical security vulnerabilities reported in recent versions of its email and collaboration software. Multiple outlets report that the fix includes a command injection issue in the Simple Network Management Protocol (SNMP) monitoring component, particularly when SNMP notifications are enabled. In addition, the update addresses multiple cross-site scripting (XSS) vulnerabilities, which could allow malicious content to execute in a user’s browser under certain conditions.

Beyond the SNMP command injection and XSS defects, the update also resolves other security problems described by sources as involving restriction bypass and server-side request forgery (SSRF). One report references Zimbra 10.1.20 as the version containing fixes for several of the issues, noting that as many as nine vulnerabilities are covered. The updates are intended to mitigate the risks associated with these vulnerabilities and reduce the likelihood of exploitation in affected deployments. Administrators are generally expected to apply the latest patches for the addressed versions to ensure the vulnerabilities are remediated.