Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug

2026-07-21T20:51:43Z81873ab1821aeaf6fa51a6b2128adc1d57b953b0c1bca8b64c12dced076d0005
7-zipactive-exploitationai-securityauthentication-bypasscommand-injectionespionageglobalprotecthugging-faceincident-responseiotip-camerasnginxpalo-alto-networkspatchingqilinransomwarerceservicenowsonicwallvpnzero-dayzimbra

What happened

Multiple high-impact vulnerabilities and active exploitation reported across widely used infrastructure and applications. Notable items: Qilin ransomware affiliates are exploiting PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) to gain VPN access; attackers are actively exploiting a pre-auth ServiceNow RCE (CVE-2026-6875) against self-hosted instances; F5 released fixes for a critical nginx heap overflow/RCE (CVE-2026-42533, CVSS 9.2). Other urgent issues include a critical SNMP monitoring command-injection in Zimbra 10.1.20, a 7-Zip RCE via crafted XZ archives, SonicWall SMA 1000(s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
81873ab1821aeaf6fa51a6b2128adc1d57b953b0c1bca8b64c12dced076d0005
Enrichment time
2026-07-21T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.