logo

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

ID: 8e75fcbb-7abe-59a9-b267-ae28db2d2bcb

STIX ID: report--8e75fcbb-7abe-59a9-b267-ae28db2d2bcb

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2026-07-11

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Zimbra has released an update to address a critical stored XSS vulnerability in the Classic Web Client that could let specially crafted emails run malicious scripts, potentially exposing mailbox information, session data, or account settings; customers are advised to update to Zimbra Collaboration Suite 10.1.19. No CVE or confirmed in-the-wild exploitation has been reported, though Zimbra XSS issues have been targeted historically.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.