Zimbra Releases Security Patch for Stored XSS Vulnerability in Classic Web Client
ID: a1857bdc-815b-5dea-be12-7f206829990d
STIX ID: report--a1857bdc-815b-5dea-be12-7f206829990d
Feed Name: GBHackers
Threat Score
Zimbra released Daffodil v10.1.19 on July 7, 2026 to address a stored cross-site scripting (XSS) vulnerability in the Classic Web Client that could execute malicious JavaScript when a crafted email is opened; the release updates the zimbra-patch and zimbra-mbox-webclient-war packages, reiterates SNMP mitigation guidance for certain upgrade paths, and urges administrators to apply the patch and review logs for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
