Zimbra update fixes nine critical vulnerabilities
๐ Zimbra Collaboration Suite 10.1.20 addresses nine vulnerabilities across commercial and open-source editions, including a permanent fix for an SNMP command injection flaw and four XSS issues in the Classic Web Client. The update also patches mailbox delegation and EWS access control problems, an SSRF in Nextcloud integration, and a bypass for email forwarding restrictions. Synacor urges administrators to upgrade promptly to prevent exploitation by threat actors.
