Security · 4h ago
Zimbra Fixes Critical SNMP Command Injection Bug
Zimbra patched nine security flaws in version 10.1.20, including a critical command injection vulnerability in the SNMP monitoring component. The bug allows remote code execution when SNMP notifications are enabled. Users are urged to update immediately.
Meridian48 take
While Zimbra addressed the flaw, the fact that SNMP notifications are often left enabled means many instances were exposed—admins should verify their configurations.
Read the full reporting
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities →
The Hacker News
zimbracommand-injection