Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN867
_____________________________________________________________________

DATE                : 28/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Zimbra versions prior to
                                      10.1.20.
 
=====================================================================
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
_____________________________________________________________________


Patch Release Update: Zimbra 10.1.20
By marilyn lee on July 20, 2026 in Product News
Patch Security Severity: High 
Deployment Risk: Low

We have released Zimbra Collaboration Suite (ZCS) v10.1.20.

This release contains fixes for multiple critical security issues
including a permanent fix for the critical SNMP vulnerability
disclosed in our recent security advisory. The release also includes
bug fixes in licensing and mail filtering.

    Zimbra 10.1.20 (Release Notes)

We strongly recommend upgrading to this version to keep your
environment secure.


Critical Security Fixes

The following issues are fixed in this release:

    A command injection vulnerability in the SNMP monitoring
component when SNMP notifications are enabled. (Permanent fix for
the vulnerability disclosed in our security advisory on 26th
June 2026)
    A stored cross-site scripting (XSS) vulnerability in the
Classic Web Client that could allow malicious attachment filenames
to execute script under specific conditions.
    A XSS vulnerability in the Classic Web Client where crafted
fields could execute malicious script under specific conditions.
    A XSS vulnerability in the Classic Web Client where a crafted
field could execute malicious script when rendered.
    A XSS vulnerability in the Classic Web Client where crafted
attachments could execute malicious script when rendered.
    A mail forwarding restriction bypass that could allow
authenticated users to exfiltrate email despite mail
forwarding restrictions being enabled.
    A security issue in the EWS extension related to access
controls.
    An authorization issue in mailbox delegation.
    A server-side request forgery (SSRF) vulnerability in the
Nextcloud integration.

Note: In line with industry best practices, information
disclosure is limited for security vulnerability fixes. 

 
Other Bug Fixes

    Licensing: Corrected “Reset to COS Value” so feature usage
counts restore correctly instead of resetting to zero.
    Mail Forwarding: Fixed admin mail redirects being blocked
when user forwarding restrictions are switched on under very
specific conditions.

If you require assistance applying the new patch or have
concerns regarding potential exposure, please raise a support
ticket here.

=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




