logo

Zimbra Releases Security Patch for Stored XSS Vulnerability in Classic Web Client

ID: a1857bdc-815b-5dea-be12-7f206829990d

STIX ID: report--a1857bdc-815b-5dea-be12-7f206829990d

Feed Name: GBHackers

Threat Score
50/100

Date Published: 2026-07-11

Date Updated: 2026-07-21

Author: Eswar

...
...

Zimbra released Daffodil v10.1.19 on July 7, 2026 to address a stored cross-site scripting (XSS) vulnerability in the Classic Web Client that could execute malicious JavaScript when a crafted email is opened; the release updates the zimbra-patch and zimbra-mbox-webclient-war packages, reiterates SNMP mitigation guidance for certain upgrade paths, and urges administrators to apply the patch and review logs for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.