logo

Zimbra urges customers to patch critical web client XSS flaw

ID: fa034272-0cb7-5d53-94c2-aca7e85bda7f

STIX ID: report--fa034272-0cb7-5d53-94c2-aca7e85bda7f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-10

Date Updated: 2026-07-19

Author: Sergiu Gatlan

...
...

Zimbra released ZCS v10.1.19 to patch a critical stored XSS vulnerability in its Classic Web Client that can be triggered by specially crafted emails to steal session data, account settings, or mailbox content; the flaw was reported by Google's Threat Analysis Group and, while not yet confirmed as exploited in the wild, is highlighted as high-risk given prior widespread abuse of Zimbra vulnerabilities by Russian state-linked APTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.