CyberNotableConfirmedDeveloping
10.0
Zimbra releases security patches for critical command injection and SSRF vulnerabilities
SecurityWeek·2 days ago
Zimbra has released patches for a critical command injection vulnerability affecting servers with SNMP notifications enabled, alongside fixes for four XSS flaws and a mail-forwarding bypass. The extent of active exploitation remains unconfirmed, but the severity of the injection flaw poses a significant risk to enterprise email infrastructure.